Skip to main content

Vendor/product archive

ory / fosite CVEs

Beta · best-effort

4 CVEs tagged to ory / fosite0 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2020-15234

Published Oct 2, 2020

ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite before version 0.34.1, the OAuth 2.0 Client's registered redirect URLs and the redirect URL prov…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15233

Published Oct 2, 2020

ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite from version 0.30.2 and before version 0.34.1, there is an issue in which an an attacker can ove…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15223

Published Sep 24, 2020

In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.34.0, the `TokenRevocationHandler` ignores errors coming from the storage. This can le…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15222

Published Sep 24, 2020

In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.31.0, when using "private_key_jwt" authentication the uniqueness of the `jti` value is…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1