Am I affected?

type your ash_authentication_oauth2_server version to check

Description

Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses.

public_ip?/1 in AshAuthentication.Oauth2Server.CIMD.ReqFetcher enforces the outbound policy for CIMD metadata fetches. It classified several address forms as publicly routable that are not: IPv4-compatible ::/96 (for example ::127.0.0.1), SIIT IPv4-translated ::ffff:0:0:0/96, and deprecated site-local fec0::/10. A returned AAAA record in one of these ranges passed the policy, so a fetch pinned to that address reached space the policy was meant to block.

This issue affects ash_authentication_oauth2_server: from 0.3.0 before 0.3.1.

Weaknesses & attack patterns

Weakness

CWE-918 · Server-Side Request Forgery (SSRF) in catalog → MITRE ↗

Attack patterns

CAPEC-664 · Server Side Request Forgery MITRE ↗

Affected — Hex / ash_authentication_oauth2_server Hex.pm ↗ Repository ↗

0.3.0 < 0.3.1 affected
every other version: unaffected
cpe cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:*
modules · source files · routines
modules 'Elixir.AshAuthentication.Oauth2Server.CIMD.ReqFetcher'
source files lib/ash_authentication/oauth2_server/cimd/req_fetcher.ex
routines 'Elixir.AshAuthentication.Oauth2Server.CIMD.ReqFetcher':public_ip?/1 · 'Elixir.AshAuthentication.Oauth2Server.CIMD.ReqFetcher':fetch/2

Affected — GitHub / ash-project/ash_authentication_oauth2_server Repository ↗

e713a9b < 268b591 affected
every other version: unaffected
cpe cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:*
modules · source files · routines
modules 'Elixir.AshAuthentication.Oauth2Server.CIMD.ReqFetcher'
source files lib/ash_authentication/oauth2_server/cimd/req_fetcher.ex
routines 'Elixir.AshAuthentication.Oauth2Server.CIMD.ReqFetcher':public_ip?/1 · 'Elixir.AshAuthentication.Oauth2Server.CIMD.ReqFetcher':fetch/2

Configurations

Reachable only when Client ID Metadata Documents are enabled (cimd_enabled?: true), so the authorize endpoint fetches attacker-suppliable metadata URLs, and an internal or loopback target resolves to one of the affected IPv6 address forms.

References

Credits

Peter Ullrich Finder Reporter
Zach Daniel / Ash Project Remediation developer
Jonatan Männchen / EEF Coordinator

CVSS breakdown

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
« All CVEs