CVE-2022-0916

An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations.
Configurations

Configuration 1 (hide)

cpe:2.3:a:logitech:options:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:39

Type Values Removed Values Added
CVSS v2 : 6.8
v3 : 8.8
v2 : 6.8
v3 : 8.4
References () https://support.logi.com/hc/en-us/articles/360025297893 - Vendor Advisory () https://support.logi.com/hc/en-us/articles/360025297893 - Vendor Advisory

Information

Published : 2022-05-03 14:15

Updated : 2024-11-21 06:39


NVD link : CVE-2022-0916

Mitre link : CVE-2022-0916

CVE.ORG link : CVE-2022-0916


JSON object : View

Products Affected

logitech

  • options
CWE
CWE-287

Improper Authentication

CWE-352

Cross-Site Request Forgery (CSRF)