@feathersjs/authentication-oauth is vulnerable to Improper Input Validation
72
High Risk
Affected versions of this package were vulnerable to improper URL and origin validation, enabling a generic OAuth redirection abuse issue. An attacker could manipulate unvalidated or weakly validated redirect/origin values to force the application to redirect sensitive OAuth responses (such as access tokens) to attacker-controlled endpoints, including look-alike or crafted URLs that bypass origin checks, resulting in token leakage and unauthorized account access.
You are affected if you are using a version that falls within the vulnerable range.
@feathersjs/authentication-oauth is vulnerable to Improper Input Validation in versions 5.0.0 - 5.0.39.
Upgrade the @feathersjs/authentication-oauth library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant