league/oauth2-server is vulnerable to Return of Wrong Status Code
15
Low Risk
Affected versions of this package return an incorrect status code. When a refresh token has expired, been revoked, cannot be decrypted, or does not belong to the correct client. In the patch version, the server correctly issues an invalid_grant error with a HTTP 400 response but in previous versions, the server incorrectly issued an invalid_request error and a HTTP 401 response. This issue has been resolved to ensure the correct handling of token-related errors and improve error reporting consistency.
You are affected if you are using a version that falls within the vulnerable range.
league/oauth2-server is vulnerable to Return of Wrong Status Code in versions 6.0.2 - 8.5.4.
Upgrade the league/oauth2-server library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant