










Applications built with the Auth0 Symphony SDK, using the Authorizer security authenticator to protect HTTP routes may accept OAuth 2.0 bearer access tokens provided through a URL query parameter, in addition to the standard Authorization header, which may increase the risk of access token exposure and replay against protected API endpoints.
>= 5.0.0-BETA0, <= 5.8.0
Upgrade auth0/symfony to version 5.9.0 or greater.
Okta would like to thank Alex Yeara for their discovery.
Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。