PT-2026-54957 · Liboauth2 · Liboauth2
CVSS v4.0
5.1
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
liboauth2 versions prior to 2.3.0
Description
An issue exists in the
oauth2 jose jwks aws alb resolve() function where the AWS ALB verifier processes the signer and kid values from an unverified JWT header. When the signer matches the configured ARN, the kid is appended to the alb base url without URL encoding or path sanitization. Because the HTTP GET request is issued before the signature is verified, a remote attacker can trigger a Server-Side Request Forgery (SSRF), forcing the server to send a GET request to an internal path of the attacker's choosing.Recommendations
Update to version 2.3.0.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Liboauth2