Duende.IdentityServer is vulnerable to Improper Authorization
82
High Risk
The pushed authorization request (PAR) endpoint in Duende.IdentityServer accepts a pushed request without checking that its client_id matches the client that authenticated to the endpoint. A party with valid credentials for one registered client can push an authorization request for a different client and receive a request_uri for it, preloading state, PKCE parameters, and scopes the victim client did not create. When AllowUnregisteredPushedRedirectUris is enabled, implicit only clients and non-https redirect URIs could also skip registration, extending the exposure to redirect based token theft for confidential clients. The fix rejects pushed requests whose client_id does not match the authenticated client and only allows unregistered redirect URIs that use https, do not belong to implicit only clients, and do not match a disallowed prefix.
You are affected if you are using a version that falls within the vulnerable range.
Duende.IdentityServer is vulnerable to Improper Authorization in versions 7.0.0 - 7.0.9, 7.1.0 - 7.1.2, 7.2.0 - 7.2.4, 7.3.0 - 7.3.4, 7.4.0 - 7.4.12 and 8.0.0 - 8.0.8.
Upgrade the Duende.IdentityServer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.