ZeroHour

CVE-2022-0916

CVSS 3.1
8.8 high
EPSS
<1%p37
Published
()
Modified
Description

An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations.

Vendors
logitech
Products
options
Weakness
CWE-287, CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.