{"id":"GHSA-hhw9-35p2-q2c5","aliases":[],"url":"https://o3.security/vulnerability/GHSA-hhw9-35p2-q2c5","summary":"Steam Socialite Provider v1 does not correctly validate openid server","details":"### Impact\nThe outdated version 1 of the Steam Socialite Provider doesn't check properly if the login comes from `steamcommunity.com`, allowing a malicious actor to substitute their own openID server.\n\n### Patches\nThis vulnerability only affects the outdated v1.x versions of the package. These are no longer maintained, users should upgrade to v3 or v4, which use a hardcoded endpoint to verify the login.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [SocialiteProviders/Providers](https://github.com/SocialiteProviders/Providers)\n* Email us at [socialite@atymic.dev](mailto:socialite@atymic.dev)","published":"2021-01-29T20:51:30Z","modified":"2024-12-02T05:44:34.357512Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"socialiteproviders/steam","fixedVersion":"3.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/SocialiteProviders/Steam/security/advisories/GHSA-hhw9-35p2-q2c5"},{"type":"WEB","url":"https://packagist.org/packages/socialiteproviders/steam"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:44:34.357512Z"}}