Am I affected?

type your ash_authentication_oauth2_server version to check

Description

Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication parameters into the WWW-Authenticate challenge header.

BearerPlug and RequireScopePlug built the Bearer resource_metadata="..." challenge by interpolating a resource_metadata URL derived from the request tenant directly into the quoted value. In a multi-tenant application that sets the Ash tenant from request-controlled data (a subdomain, the Host, a path segment, or a header), a tenant containing a " closes the quoted value and appends attacker-chosen auth-params, including a second resource_metadata URL pointing at an attacker-controlled authorization server that spec-following clients follow. Carriage returns and line feeds are rejected by Plug, so this is parameter injection within one header, not response splitting.

This issue affects ash_authentication_oauth2_server: from 0.1.3 before 0.3.1.

Weaknesses & attack patterns

Weakness

CWE-116 · Improper Encoding or Escaping of Output in catalog → MITRE ↗

Attack patterns

CAPEC-153 · Input Data Manipulation MITRE ↗

Affected — Hex / ash_authentication_oauth2_server Hex.pm ↗ Repository ↗

0.1.3 < 0.3.1 affected
every other version: unaffected
cpe cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:*
modules · source files · routines
modules 'Elixir.AshAuthentication.Phoenix.Oauth2Server.BearerPlug' · 'Elixir.AshAuthentication.Phoenix.Oauth2Server.RequireScopePlug'
source files lib/ash_authentication_phoenix/oauth2_server/bearer_plug.ex · lib/ash_authentication_phoenix/oauth2_server/require_scope_plug.ex
routines 'Elixir.AshAuthentication.Phoenix.Oauth2Server.BearerPlug':call/2 · 'Elixir.AshAuthentication.Phoenix.Oauth2Server.RequireScopePlug':call/2

Affected — GitHub / ash-project/ash_authentication_oauth2_server Repository ↗

99de0a1 < 09f9747 affected
every other version: unaffected
cpe cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:*
modules · source files · routines
modules 'Elixir.AshAuthentication.Phoenix.Oauth2Server.BearerPlug' · 'Elixir.AshAuthentication.Phoenix.Oauth2Server.RequireScopePlug'
source files lib/ash_authentication_phoenix/oauth2_server/bearer_plug.ex · lib/ash_authentication_phoenix/oauth2_server/require_scope_plug.ex
routines 'Elixir.AshAuthentication.Phoenix.Oauth2Server.BearerPlug':call/2 · 'Elixir.AshAuthentication.Phoenix.Oauth2Server.RequireScopePlug':call/2

Configurations

Reachable only in a multi-tenant application that derives the Ash tenant from request-controlled input (subdomain, Host, path, or header) and uses BearerPlug or RequireScopePlug; the tenant reaches the challenge through the server's tenant-aware resource_url.

References

Credits

Peter Ullrich Finder Reporter
Zach Daniel / Ash Project Remediation developer
Jonatan Männchen / EEF Coordinator

CVSS breakdown

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N
« All CVEs