1.9.0.post1
15 years ago
9 years ago
Known vulnerabilities in the oauth2 package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Insecure Randomness. The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack. How to fix Insecure Randomness? Upgrade to version | [,1.9rc1) |
How to fix Replay Attack? Upgrade to version | [,1.9rc1) |