socialiteproviders/steam
Steam OpenID Provider for Laravel Socialite
Activity
- Latest release
- 1mo ago
- Total releases
- 16
- Cadence
- ~40 days
- Last 12 months
- 2
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Jan 25, 2017
| Version | Released | |
|---|---|---|
4.4.1
patch
| ||
4.4.0
minor
| ||
4.3.1
patch
| ||
4.3.0
minor
| ||
4.2.0
minor
| ||
4.1.1
patch
| ||
4.1.0
minor
| ||
4.0.0
major
| ||
v3.1.1
patch
| ||
v3.1.0
minor
| ||
v3.0.2
patch
| ||
v3.0.1
patch
| ||
v3.0.0
major
| ||
v1.1
minor
1 CVE
GHSA-hhw9-35p2-q2c5
Jan 29, 2021
Steam Socialite Provider v1 does not correctly validate openid server
Critical
ImpactThe outdated version 1 of the Steam Socialite Provider doesn't check properly if the login comes from PatchesThis vulnerability only affects the outdated v1.x versions of the package. These are no longer maintained, users should upgrade to v3 or v4, which use a hardcoded endpoint to verify the login. For more informationIf you have any questions or comments about this advisory:
Affected versions
v1.0.0
v1.0.1
v1.1
Fixed in
3.0
References Updated Dec 02, 2024 · Source: OSV.dev | ||
v1.0.1
patch
1 CVE
GHSA-hhw9-35p2-q2c5
Jan 29, 2021
Steam Socialite Provider v1 does not correctly validate openid server
Critical
ImpactThe outdated version 1 of the Steam Socialite Provider doesn't check properly if the login comes from PatchesThis vulnerability only affects the outdated v1.x versions of the package. These are no longer maintained, users should upgrade to v3 or v4, which use a hardcoded endpoint to verify the login. For more informationIf you have any questions or comments about this advisory:
Affected versions
v1.0.0
v1.0.1
v1.1
Fixed in
3.0
References Updated Dec 02, 2024 · Source: OSV.dev | ||
v1.0.0
initial
1 CVE
GHSA-hhw9-35p2-q2c5
Jan 29, 2021
Steam Socialite Provider v1 does not correctly validate openid server
Critical
ImpactThe outdated version 1 of the Steam Socialite Provider doesn't check properly if the login comes from PatchesThis vulnerability only affects the outdated v1.x versions of the package. These are no longer maintained, users should upgrade to v3 or v4, which use a hardcoded endpoint to verify the login. For more informationIf you have any questions or comments about this advisory:
Affected versions
v1.0.0
v1.0.1
v1.1
Fixed in
3.0
References Updated Dec 02, 2024 · Source: OSV.dev |