angular-auth-oidc-client is vulnerable to Origin Validation Error
20
Low Risk
Affected versions of this package are vulnerable to OpenID Connect Issuer Validation Bypass due to a missing validation of the issuer field in the discovered OpenID Configuration document against the expected authority URL. An attacker could exploit this by poisoning a reverse proxy cache or via a man-in-the-middle attack to redirect discovery requests to a malicious domain, which would then supply a fraudulent configuration document with a matching issuer.
You are affected if you are using a version that falls within the vulnerable range.
angular-auth-oidc-client is vulnerable to Origin Validation Error in versions 11.6.0 - 19.0.2.
Upgrade the angular-auth-oidc-client library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant