First published: Mon Mar 31 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Drupal OAuth2 Client allows Cross Site Request Forgery. This issue affects OAuth2 Client: from 0.0.0 before 4.1.3.
Credit: mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal OAuth2 Client | <4.1.3>=undefined | |
composer/drupal/oauth2_client | <4.1.3 | 4.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31684 is considered a critical severity vulnerability due to its potential to allow unauthorized actions through Cross-Site Request Forgery.
To fix CVE-2025-31684, update the Drupal OAuth2 Client module to version 4.1.3 or later.
CVE-2025-31684 affects all versions of Drupal OAuth2 Client prior to version 4.1.3.
CVE-2025-31684 enables a Cross-Site Request Forgery (CSRF) attack, allowing unauthorized actions to be performed by users.
No official workaround is provided for CVE-2025-31684; the recommended action is to update to the secure version.