PT-2026-86925 · Ash+1 · Ash Authentication Oauth2 Server
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N |
Summary
Use of Cache Containing Sensitive Information vulnerability in ash-project ash authentication oauth2 server allows a shared HTTP cache to serve one tenant's OAuth discovery metadata to another tenant's clients.
The RFC 8414 and RFC 9728 metadata endpoints in
AshAuthentication.Phoenix.Oauth2Server.ProtocolRouter return tenant-specific values (issuer, authorization endpoint, token endpoint, jwks uri) when a tenant is set, but sent them with Cache-Control: public, max-age=3600 and no Vary. When the tenant is derived from something other than the URL (a header or the Host) and a shared cache sits in front, the cache key is the URL alone, so a stored response for one tenant is served to another for up to an hour. Affected clients may then send authorization codes and secrets to the wrong tenant's token endpoint and validate tokens against the wrong keys.This issue affects ash authentication oauth2 server: from 0.1.3 before 0.3.1.
Configurations
Reachable only in a multi-tenant deployment where the tenant is derived from outside the request URL (a header or the
Host) and a shared HTTP cache (CDN, reverse proxy) sits in front of the metadata endpoints.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ash Authentication Oauth2 Server