Simple OAuth (OAuth2) & OpenID Connect - Moderately critical - Access bypass - SA-CONTRIB-2022-002
Project: Simple OAuth (OAuth2) & OpenID Connect
Date: 2022-January-05
Security risk: Moderately critical 13∕25
Vulnerability: Access bypass
Description
This module enables you to implement OAuth 2.0 authentication for Drupal.
The module doesn't sufficiently verify client secret keys for "confidential" OAuth 2.0 clients when using certain grant types. The token refresh and client credentials grants are not affected.