Логотип exploitDog
bind:CVE-2025-14546
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-14546

Количество 2

Количество 2

nvd логотип

CVE-2025-14546

около 2 месяцев назад

Versions of the package fastapi-sso before 0.19.0 are vulnerable to Cross-site Request Forgery (CSRF) due to the improper validation of the OAuth state parameter during the authentication callback. While the get_login_url method allows for state generation, it does not persist the state or bind it to the user's session. Consequently, the verify_and_process method accepts the state received in the query parameters without verifying it against a trusted local value. This allows a remote attacker to trick a victim into visiting a malicious callback URL, which can result in the attacker's account being linked to the victim's internal account.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-hp6r-r9vc-q8wx

около 2 месяцев назад

FastAPI SSP is vulnerable to Cross-site Request Forgery (CSRF) through improper OAuth parameter validation

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-14546

Versions of the package fastapi-sso before 0.19.0 are vulnerable to Cross-site Request Forgery (CSRF) due to the improper validation of the OAuth state parameter during the authentication callback. While the get_login_url method allows for state generation, it does not persist the state or bind it to the user's session. Consequently, the verify_and_process method accepts the state received in the query parameters without verifying it against a trusted local value. This allows a remote attacker to trick a victim into visiting a malicious callback URL, which can result in the attacker's account being linked to the victim's internal account.

CVSS3: 6.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-hp6r-r9vc-q8wx

FastAPI SSP is vulnerable to Cross-site Request Forgery (CSRF) through improper OAuth parameter validation

CVSS3: 6.3
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу