CVE-2021-41580 affects the passport-oauth2 package before version 1.6.1 for Node.js, specifically concerning how it handles access token acquisition failures. The vulnerability arises when an OAuth identity provider returns an HTTP 200 status code for an authentication failure, and the application grants authorization without validating the token's usability. This medium-severity vulnerability (CVSS 5.3) has a low impact, potentially leading to unauthorized access (C:L), but does not affect integrity or availability. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.1CPE matchmatch criteria | cpe:2.3:a:passportjs:passport-oauth2:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.