CVE-2022-0916

An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations.
Configurations

Configuration 1 (hide)

cpe:2.3:a:logitech:options:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:39

Type Values Removed Values Added
References () https://support.logi.com/hc/en-us/articles/360025297893 - Vendor Advisory () https://support.logi.com/hc/en-us/articles/360025297893 - Vendor Advisory
CVSS v2 : 6.8
v3 : 8.8
v2 : 6.8
v3 : 8.4

10 May 2022, 23:59

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 8.8
References (MISC) https://support.logi.com/hc/en-us/articles/360025297893 - (MISC) https://support.logi.com/hc/en-us/articles/360025297893 - Vendor Advisory
CPE cpe:2.3:a:logitech:options:*:*:*:*:*:*:*:*
CWE CWE-352

03 May 2022, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-03 14:15

Updated : 2024-11-21 06:39


NVD link : CVE-2022-0916

Mitre link : CVE-2022-0916

CVE.ORG link : CVE-2022-0916


JSON object : View

Products Affected

logitech

  • options
CWE
CWE-287

Improper Authentication

CWE-352

Cross-Site Request Forgery (CSRF)