strapi-plugin-sso is vulnerable to Cross-Site Request Forgery (CSRF)
55
Medium Risk
Affected versions of this package are vulnerable to Cross-Site Request Forgery (CSRF) due to missing validation of the state parameter in OAuth 2.0 authorization flows. An attacker could exploit a lack of a securely generated state parameter in an OAuth login by tricking a victim into initiating the process and then intercepting the callback. It could allow the attacker to hijack the session or force unintended authentication, enabling the submission of malicious authorization codes or redirect URIs to compromise user accounts.
You are affected if you are using a version that falls within the vulnerable range.
strapi-plugin-sso is vulnerable to Cross-Site Request Forgery (CSRF) in versions 0.3.1 - 0.4.6 and 1.0.0 - 1.0.5.
Upgrade the strapi-plugin-sso library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant