PT-2026-86927 · Ash+1 · Ash Authentication Oauth2 Server
CVSS v4.0
6.3
Média
| Vetor | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N |
Summary
Server-Side Request Forgery (SSRF) vulnerability in ash-project ash authentication oauth2 server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses.
public ip?/1 in AshAuthentication.Oauth2Server.CIMD.ReqFetcher enforces the outbound policy for CIMD metadata fetches. It classified several address forms as publicly routable that are not: IPv4-compatible ::/96 (for example ::127.0.0.1), SIIT IPv4-translated ::ffff:0:0:0/96, and deprecated site-local fec0::/10. A returned AAAA record in one of these ranges passed the policy, so a fetch pinned to that address reached space the policy was meant to block.This issue affects ash authentication oauth2 server: from 0.3.0 before 0.3.1.
Configurations
Reachable only when Client ID Metadata Documents are enabled (
cimd enabled?: true), so the authorize endpoint fetches attacker-suppliable metadata URLs, and an internal or loopback target resolves to one of the affected IPv6 address forms.Exploit
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ash Authentication Oauth2 Server