GHSA-5p73-qg2v-383h
Dashboard / Vulnerabilities / GHSA-5p73-qg2v-383h
Summary: LTI 1.3 Tool Library's Nonce Claim Value not validated against nonce value sent in Authentication Request before v5.0
Details: ### Impact Nonce Claim Value was not being validated against the nonce value sent in the Authentication Request. ### Patches Users should upgrade to version 5.0 immediately ### Workarounds None.
References: https://github.com/packbackbooks/lti-1-3-php-library/security/advisories/GHSA-5p73-qg2v-383h, https://nvd.nist.gov/vuln/detail/CVE-2022-31158, https://github.com/packbackbooks/lti-1-3-php-library, https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest
Affected packages
Package
Name: packbackbooks/lti-1-3-php-library
Purl: pkg:composer/packbackbooks/lti-1-3-php-library
Affected ranges
Type: ECOSYSTEM
Events:
