Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Simple OAuth (OAuth2) & OpenID Connect allows Authentication Bypass.This issue affects Simple OAuth (OAuth2) & OpenID Connect: from 6.0.0 before 6.0.7.
Problem types
CWE-288 Authentication Bypass Using an Alternate Path or Channel
Product status
6.0.0 (semver) before 6.0.7
Credits
coffeemakr
Bojan Bogdanovic (bojan_dev)
coffeemakr
Juraj Nemec (poker10)
Greg Knaddison (greggles)
Juraj Nemec (poker10)
References
www.drupal.org/sa-contrib-2025-114