LTI 1.3 Tool Library's Nonce Claim Value not validated against nonce value sent in Authentication Request before v5.0
High severity
GitHub Reviewed
Published
Jul 15, 2022
in
packbackbooks/lti-1-3-php-library
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Jul 15, 2022
Published to the GitHub Advisory Database
Jul 15, 2022
Reviewed
Jul 15, 2022
Last updated
Jan 27, 2023
Impact
Nonce Claim Value was not being validated against the nonce value sent in the Authentication Request.
Patches
Users should upgrade to version 5.0 immediately
Workarounds
None.
References