VYPR

OAuth 2.0 Server

by ApiFest

CVEs (1)

  • CVE-2020-26877Jun 29, 2022
    risk 0.00cvss epss 0.00

    ApiFest OAuth 2.0 Server 0.3.1 does not validate the redirect URI in accordance with RFC 6749 and is susceptible to an open redirector attack. Specifically, it directly sends an authorization code to the redirect URI submitted with the authorization request, without checking…