Vulnerability PYSEC-2022-269
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
4 years ago
September 09, 2022 at 09:15 PM UTC
No summary available
3.1.1 - 3.2.0
3.1.1 - 3.2.0
Details
OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malicious redirect uri can cause denial of service. An attacker can also leverage usage of uri_validate functions depending where it is used. OAuthLib applications using OAuth2.0 provider support or use directly uri_validate are affected by this issue. Version 3.2.1 contains a patch. There are no known workarounds.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
2 hours ago
Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)
3.0.0 - 3.3.1 GHSA-xpv3-w29h-x7cv
3.0.0 - 3.3.1 GHSA-xpv3-w29h-x7cv
Medium Risk
2 hours ago
Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation
0.6.1 - 3.3.1 GHSA-hj66-6f7g-4r5v
0.6.1 - 3.3.1 GHSA-hj66-6f7g-4r5v
Medium Risk
4 years ago
OAuthLib vulnerable to DoS when attacker provides malicious IPV6 URI
3.1.1 - 3.2.1 GHSA-3pgj-pg6c-r5p7
3.1.1 - 3.2.1 GHSA-3pgj-pg6c-r5p7
Impacted packages
Timeline
Published
4 years ago
September 09, 2022 at 09:15 PM UTC
Fixed (3.2.1)
4 years ago
September 09, 2022 at 08:15 PM UTC
Last Modified
2 years ago
November 08, 2023 at 04:10 AM UTC