描述
The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers.
AI分析AI驱动
受影响产品
dash10oauth_server
参考资料
- https://security.dxw.com/advisories/the-oauth2-complete-plugin-for-wordpress-uses-a-pseudorandom-number-generator-which-is-non-cryptographically-secure/Third Party Advisory
- https://wordpress.org/plugins/oauth2-provider/#developersProductVendor Advisory
- https://security.dxw.com/advisories/the-oauth2-complete-plugin-for-wordpress-uses-a-pseudorandom-number-generator-which-is-non-cryptographically-secure/Third Party Advisory
- https://wordpress.org/plugins/oauth2-provider/#developersProductVendor Advisory