
Cloud Vulnerability DB
A community-led vulnerabilities database
The Steam Socialite Provider version 1.x contains a critical security vulnerability identified as GHSA-hhw9-35p2-q2c5, discovered and disclosed on January 29, 2021. The vulnerability affects the socialiteproviders/steam Composer package versions below 1.1. This security issue impacts the OpenID authentication implementation for Laravel Socialite when integrating with Steam authentication (GitHub Advisory).
The vulnerability is classified as Critical severity and is identified with CWE-346. The core issue lies in the improper validation of OpenID server authentication, where version 1 of the Steam Socialite Provider fails to properly verify if the login originates from steamcommunity.com (GitHub Advisory).
The vulnerability allows malicious actors to substitute their own OpenID server during the authentication process, potentially compromising the authentication mechanism. This could lead to unauthorized access and potential impersonation of Steam users within applications using the affected package (GitHub Advisory).
The vulnerability enables attackers to perform authorization domain spoofing. Without proper host validation, fraudsters could potentially gain unauthorized access to the application under other users' credentials (Packagist).
Users are strongly advised to upgrade to version 3 or 4 of the package, which implements a hardcoded endpoint to verify the login. The newer versions also include additional security features such as the 'allowed_hosts' configuration option to protect against authorization domain spoofing (GitHub Advisory, Packagist).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."