{"id":"GHSA-hhw9-35p2-q2c5","summary":"Steam Socialite Provider v1 does not correctly validate openid server","details":"### Impact\nThe outdated version 1 of the Steam Socialite Provider doesn't check properly if the login comes from `steamcommunity.com`, allowing a malicious actor to substitute their own openID server.\n\n### Patches\nThis vulnerability only affects the outdated v1.x versions of the package. These are no longer maintained, users should upgrade to v3 or v4, which use a hardcoded endpoint to verify the login.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [SocialiteProviders/Providers](https://github.com/SocialiteProviders/Providers)\n* Email us at [socialite@atymic.dev](mailto:socialite@atymic.dev)","modified":"2024-12-02T05:44:34.357512Z","published":"2021-01-29T20:51:30Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2021-01-29T20:39:56Z","nvd_published_at":null,"cwe_ids":["CWE-346"]},"references":[{"type":"WEB","url":"https://github.com/SocialiteProviders/Steam/security/advisories/GHSA-hhw9-35p2-q2c5"},{"type":"WEB","url":"https://packagist.org/packages/socialiteproviders/steam"}],"affected":[{"package":{"name":"socialiteproviders/steam","ecosystem":"Packagist","purl":"pkg:composer/socialiteproviders/steam"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0"}]}],"versions":["v1.0.0","v1.0.1","v1.1"],"database_specific":{"last_known_affected_version_range":"\u003c 1.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/01/GHSA-hhw9-35p2-q2c5/GHSA-hhw9-35p2-q2c5.json"}}],"schema_version":"1.9.0"}