Описание
OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malicious redirect uri can cause denial of service. An attacker can also leverage usage of uri_validate
functions depending where it is used. OAuthLib applications using OAuth2.0 provider support or use directly uri_validate
are affected by this issue. Version 3.2.1 contains a patch. There are no known workarounds.
A flaw was found in python-oauthlib. This flaw allows an attacker providing a malicious redirect URI to cause a denial of service to OAuthLib's web application.
Меры по смягчению последствий
The redirect_uri can be verified in the web toolkit before OAuthLib is called. Check to see if :
is present to reject the request can prevent the denial of service, assuming no port or IPv6 is fundamentally required.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ansible Automation Platform 1.2 | ansible-tower | Affected | ||
Red Hat Ansible Automation Platform 2 | ansible-automation-platform-24/ee-29-rhel8 | Affected | ||
Red Hat Ansible Automation Platform 2 | ansible-automation-platform-24/ee-minimal-rhel9 | Affected | ||
Red Hat Ansible Automation Platform 2 | ansible-automation-platform-24/ee-supported-rhel9 | Affected | ||
Red Hat Ansible Automation Platform 2 | ansible-automation-platform-24/platform-resource-runner-rhel8 | Affected | ||
Red Hat Ansible Automation Platform 2 | ansible-automation-platform-25/ansible-builder-rhel8 | Affected | ||
Red Hat Ansible Automation Platform 2 | ansible-automation-platform-25/ee-cloud-services-rhel9 | Affected | ||
Red Hat Ansible Automation Platform 2 | automation-controller | Affected | ||
Red Hat OpenShift Container Platform 4 | openshift4/ztp-site-generate-rhel8 | Affected | ||
Red Hat OpenStack Platform 16.1 | openstack-mistral | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malicious redirect uri can cause denial of service. An attacker can also leverage usage of `uri_validate` functions depending where it is used. OAuthLib applications using OAuth2.0 provider support or use directly `uri_validate` are affected by this issue. Version 3.2.1 contains a patch. There are no known workarounds.
OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malicious redirect uri can cause denial of service. An attacker can also leverage usage of `uri_validate` functions depending where it is used. OAuthLib applications using OAuth2.0 provider support or use directly `uri_validate` are affected by this issue. Version 3.2.1 contains a patch. There are no known workarounds.
OAuthLib is an implementation of the OAuth request-signing logic for P ...
OAuthLib vulnerable to DoS when attacker provides malicious IPV6 URI
EPSS
6.5 Medium
CVSS3