Vulnerability GHSA-3pgj-pg6c-r5p7

Medium Risk
MEDIUM RISK
CVSS Score: 5.7
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
4 years ago
September 16, 2022 at 09:02 PM UTC
OAuthLib vulnerable to DoS when attacker provides malicious IPV6 URI
3.1.1 - 3.2.1
3.1.1 - 3.2.1

Summary

OAuthLib vulnerable to DoS when attacker provides malicious IPV6 URI

Details

Impact

  • Attacker providing malicious redirect uri can cause DoS to oauthlib's web application.
  • Attacker can also leverage usage of uri_validate functions depending where it is used.

What kind of vulnerability is it? Who is impacted?

Oauthlib applications using OAuth2.0 provider support or use directly uri_validate function.

Patches

Has the problem been patched? What versions should users upgrade to?

Issue fixed in 3.2.2 release.

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

The redirect_uri can be verified in web toolkit (i.e bottle-oauthlib, django-oauth-toolkit, ...) before oauthlib is called. A sample check if : is present to reject the request can prevent the DoS, assuming no port or IPv6 is fundamentally required.

References

Attack Vector:

PoC

is_absolute_uri("http://[:::::::::::::::::::::::::::::::::::::::]/path")

Acknowledgement

Special thanks to Sebastian Chnelik - PyUp.io

Impacted packages

Timeline

Published
4 years ago
September 16, 2022 at 09:02 PM UTC
Fixed (3.2.2)
3 years ago
October 17, 2022 at 08:04 PM UTC
Last Modified
1 year ago
October 07, 2024 at 05:04 PM UTC