Project:
Date:
2020-October-14
Vulnerability:
SQL Injection
Affected versions:
1.0.0
Description:
This module enables you login into any OAuth 2.0 compliant application using Drupal credentials.
The 8.x branch of the module is vulnerable to SQL injection.
Solution:
Install the latest version:
- If you use the Drupal OAuth Server module for Drupal 8.x, upgrade to 8.x-1.1
Reported By:
Fixed By:
- Gaurav Sood
- Greg Knaddison of the Drupal Security Team
- Samuel Mortenson of the Drupal Security Team
Coordinated By:
- Michael Hess of the Drupal Security Team