yiisoft/yii2-authclient
External authentication via OAuth and OpenID for the Yii framework
Activity
- Latest release
- 1y ago
- Total releases
- 36
- Cadence
- ~3 months
- Last 12 months
- 0
Reach
- Stars
- —
Details
- License
- BSD-3-Clause
- First release
- Apr 13, 2014
| Version | Released | |
|---|---|---|
2.2.17
patch
|
2.2.17
patch
Dependencies (3)
Changelog
Compare changes
|
|
2.2.16
patch
| ||
2.2.15
patch
| ||
2.2.14
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.13
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.12
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.11
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.10
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.9
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.8
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.7
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.6
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.5
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.4
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.3
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.2
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.1
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.2.0
minor
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.8
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.7
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.6
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.5
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.4
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.3
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.2
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.1
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.1.0
minor
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.6
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.5
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.4
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.3
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.2
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.1
patch
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0
initial
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0-rc
pre
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0-beta
pre
2 CVEs
CVE-2023-50708
GHSA-w8vh-p74j-x9xp
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
0.0
/ 10
None
Network
High
None
Required
Changed
None
None
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
Affected Code:
PatchesHas the problem been patched? What versions should users upgrade to? TBD: Replace strcmp with WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not as far as I see. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-50714
GHSA-rw54-6826-c8j5
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
ImpactWhat kind of vulnerability is it? Who is impacted? Original Report:
PatchesHas the problem been patched? What versions should users upgrade to? 2.2.15 WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? not known yet. ReferencesAre there any links users can visit to find out more? Affected versions
2.0.0
2.0.0-beta
2.0.0-rc
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.1
2.1.2
+ 21 more Show less
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
Fixed in
2.2.15
References
Updated Sep 10, 2026 · Source: OSV.dev |