Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9041 | Drupal OAuth2 Client Cross-Site Request Forgery (CSRF) |
Github GHSA |
GHSA-6chf-hhqf-749c | Drupal OAuth2 Client Cross-Site Request Forgery (CSRF) |
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2025-013 |
|
Thu, 28 Aug 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mskcc
Mskcc oauth2 Client |
|
| CPEs | cpe:2.3:a:mskcc:oauth2_client:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Mskcc
Mskcc oauth2 Client |
Tue, 29 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 31 Mar 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Request Forgery (CSRF) vulnerability in Drupal OAuth2 Client allows Cross Site Request Forgery.This issue affects OAuth2 Client: from 0.0.0 before 4.1.3. | |
| Title | OAuth2 Client - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-013 | |
| Weaknesses | CWE-352 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2025-04-29T15:33:07.247Z
Reserved: 2025-03-31T21:30:15.359Z
Link: CVE-2025-31684
Updated: 2025-04-29T15:32:40.211Z
Status : Analyzed
Published: 2025-03-31T22:15:20.993
Modified: 2025-08-28T14:52:08.737
Link: CVE-2025-31684
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA