Описание
DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then use tokens to disconnect victims' cloud storage connectors.
Ссылки
EPSS
Процентиль: 4%
0.0014
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-346
Связанные уязвимости
CVSS3: 5.4
github
4 дня назад
DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then use tokens to disconnect victims' cloud storage connectors.
EPSS
Процентиль: 4%
0.0014
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-346