Описание
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when all of the following are true: Use of skip_auth_routes or the legacy skip_auth_regex; use of patterns that can be widened by attacker-controlled suffixes, such as ^/foo/.*/bar$ causing potential exposure of /foo/secret; and protected upstream applications that interpret # as a fragment delimiter or otherwise route the request to the protected base path. In deployments that rely on these settings, an unauthenticated attacker can send a crafted request containing a number sign in the path, including the browser-safe encoded form %23, so that OAuth2 Proxy matches a public allowlist rule while the backend serves a protected resource. Deployments that do not use these skip-auth options, or that only allow exact public paths with tightly scoped method and path rules, are not affected. A fix has been implemented in version 7.15.2 to normalize request paths more conservatively before skip-auth matching so fragment content does not influence allowlist decisions. Users who cannot upgrade immediately can reduce exposure by tightening or removing skip_auth_routes and skip_auth_regex rules, especially patterns that use broad wildcards across path segments. Recommended mitigations include replacing broad rules with exact, anchored public paths and explicit HTTP methods; rejecting requests whose path contains %23 or # at the ingress, load balancer, or WAF level; and/or avoiding placing sensitive application paths behind broad skip_auth_routes rules.
A flaw was found in OAuth2 Proxy. An unauthenticated attacker can exploit a configuration-dependent authentication bypass by sending a crafted request containing a number sign (#) in the path. This allows the OAuth2 Proxy to incorrectly match a public allowlist rule, leading to the exposure of protected resources from the backend application. This vulnerability can result in unauthorized access to sensitive information.
Отчет
This flaw in OAuth2 Proxy allows an unauthenticated attacker to bypass authentication. Exploitation requires a specific configuration utilizing skip_auth_routes or skip_auth_regex with broad wildcard patterns, combined with a backend application that interprets the '#' character as a fragment delimiter. Red Hat deployments are only affected if these non-default configurations are in place, potentially exposing protected resources.
Меры по смягчению последствий
To mitigate this issue, review and tighten skip_auth_routes and skip_auth_regex configurations in OAuth2 Proxy, replacing broad wildcard patterns with exact, anchored public paths and explicit HTTP methods. Additionally, consider implementing ingress, load balancer, or Web Application Firewall (WAF) rules to reject requests containing %23 or '#' in the path. Avoid placing sensitive application paths behind broadly defined skip_auth_routes rules. Configuration changes to OAuth2 Proxy may require a service restart to take effect, which could temporarily impact service availability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ceph Storage 9 | rhceph/oauth2-proxy-rhel9 | Affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when all of the following are true: Use of `skip_auth_routes` or the legacy `skip_auth_regex`; use of patterns that can be widened by attacker-controlled suffixes, such as `^/foo/.*/bar$` causing potential exposure of `/foo/secret`; and protected upstream applications that interpret `#` as a fragment delimiter or otherwise route the request to the protected base path. In deployments that rely on these settings, an unauthenticated attacker can send a crafted request containing a number sign in the path, including the browser-safe encoded form `%23`, so that OAuth2 Proxy matches a public allowlist rule while the backend serves a protected resource. Deployments that do not use these skip-auth options, or that only allow exact public paths with tightly scoped method and path rules, are not affected.
OAuth2 Proxy is a reverse proxy that provides authentication using OAu ...
OAuth2 Proxy has an Authentication Bypass via Fragment Confusion in skip_auth_routes and skip_auth_regex
7.5 High
CVSS3