Vulnerabilities/

Improper Authorization in react-oauth-flow

Severity:
High

Description

All versions of react-oauth-flow fail to properly implement the OAuth protocol. The package stores secrets in the front-end code. Instead of using a public OAuth client, it uses a confidential client on the browser. This may allow attackers to compromise server credentials.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
react-oauth-flow
Anything's wrong? Let us know Last updated on January 09, 2023