Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
better-auth before 1.6.11 Insecure Cryptographic Defaults via oidcProvider
Vulnerability Description
better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned tokens or intercept authorization codes when PKCE plain is used instead of the required S256 method.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Vulnerability Type
使用已被攻破或存在风险的密码学算法
Vulnerability Title
better-auth 加密问题漏洞
Vulnerability Description
better-auth是better-auth团队开源的一个身份验证框架。 better-auth 1.6.11之前版本存在加密问题漏洞,该漏洞源于oidcProvider和mcp插件存在不安全的加密默认值,宣传none算法并默认接受明文PKCE,可能导致攻击者利用算法协商接受未签名令牌或拦截授权码。
CVSS Information
N/A
Vulnerability Type
N/A