VYPR

OpenID Connect reference implementation

by Nginx

CVEs (1)

  • CVE-2024-10318MedNov 6, 2024
    risk 0.35cvss 5.4epss 0.00

    A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although the attacker cannot log in…