verbb/social-login is vulnerable to Improper Authentication
91
Critical Risk
Affected versions of this package allow inactive users to log in because the authentication logic does not properly enforce the account status. This improper authentication lets deactivated accounts regain access when they should be blocked.
You are affected if you are using a version that falls within the vulnerable range.
verbb/social-login is vulnerable to Improper Authentication in versions 1.0.0 - 1.0.23 and 2.0.0 - 2.0.11.
Upgrade the verbb/social-login library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant