Description

OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

Description source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 1.26.4affected
GitHub AdvisoryBefore 1.27.0 · Fixed in 1.27.0affected

References

6