Intel

AIKIDO-2024-10081

oauth4webapi is vulnerable to Authentication Bypass by Capture-replay

Authentication Bypass by Capture-replay Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 3, 2024

15

Low Risk

This Affects:

JSoauth4webapi
2.8.0 - 2.8.0
Fixed in 2.8.1
Are you affected? Scan for Free

TL;DR

Affected versions of the oauth4webapi library are vulnerable to authentication bypass by capture-replay because the DPoP (demonstrating proof of possession) iat (issued at) timestamp is not checked. This flaw allows a malicious user to sniff network traffic and bypass authentication by replaying the captured message to the server, achieving the same effect as the original request (or with minimal changes).

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

oauth4webapi is vulnerable to Authentication Bypass by Capture-replay in versions 2.8.0 - 2.8.0.

How to fix this

Upgrade the oauth4webapi library to the patch version.