Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal OpenID Connect / OAuth client allows Authentication Bypass.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0.
Problem types
CWE-288 Authentication Bypass Using an Alternate Path or Channel
Product status
0.0.0 (semver) before 1.5.0
Credits
Kimberley Massey (kimberleycgm)
Kimberley Massey (kimberleycgm)
Philip Frilling (pfrilling)
Damien McKenna (damienmckenna)
Greg Knaddison (greggles)
Juraj Nemec (poker10)
References
www.drupal.org/sa-contrib-2026-026