drupal/openid_connect is vulnerable to Access bypass
35
Low Risk
Affected versions of this package are affected by an access control bypass vulnerability due to insufficient validation of the uniqueness of certain user fields depending on the database engine and its collation settings. Because uniqueness checks may behave inconsistently across different database configurations, an attacker could register an account using the same email address as an existing user. This could lead to authentication or account-association confusion and potential data integrity issues.
You are affected if you are using a version that falls within the vulnerable range.
drupal/openid_connect is vulnerable to Access bypass in versions 1.0.0 - 1.4.0.
Upgrade the drupal/openid_connect library to the patch version and check existing accounts affected by this issue.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant