Skip to content

Use of a Broken or Risky Cryptographic Algorithm in packbackbooks/lti-1-3-php-library

High
dbhynds published GHSA-5p73-qg2v-383h Jul 15, 2022

Package

composer packbackbooks/lti-1-3-php-library (Composer)

Affected versions

< 5.0

Patched versions

5.0

Description

Impact

Nonce Claim Value was not being validated against the nonce value sent in the Authentication Request.

Patches

Users should upgrade to version 5.0 immediately

Workarounds

None.

References

More Information

This was fixed as part of https://github.com/packbackbooks/lti-1-3-php-library-ghsa-768m-5w34-2xf5/pull/1

Severity

High

CVE ID

CVE-2022-31158

Weaknesses