CVE-2024-13301: OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client) - Critical - Cross Site Scripting - SA-CONTRIB-2024-067
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client) allows Cross-Site Scripting (XSS).This issue affects OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client): from 3.0.0 before 3.44.0, from 4.0.0 before 4.0.19.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13301?
CVE-2024-13301 has been classified as a high-severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2024-13301?
To fix CVE-2024-13301, update the Drupal OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client) to the latest version available.
What products are affected by CVE-2024-13301?
CVE-2024-13301 affects the Drupal OAuth & OpenID Connect Single Sign On – SSO plugin, specifically versions between 3.0.0 to 3.44.0 and 4.0.0 to 4.0.19.
What potential impacts does CVE-2024-13301 have on my website?
CVE-2024-13301 can lead to Cross-Site Scripting (XSS), allowing attackers to inject malicious scripts into web pages viewed by users.
Is there a workaround for CVE-2024-13301?
Currently, there is no known workaround for CVE-2024-13301; the recommended approach is to upgrade to a patched version.