boruta is vulnerable to Server-Side Request Forgery (SSRF)
55
Medium Risk
Boruta fetches attacker-controlled URIs from request_uri on the authorization endpoint and from jwks_uri during dynamic client registration and client JWKS refresh, after only checking that the URI has a scheme. Those GETs go through Finch with no HTTPS requirement, host allowlist, private-range blocking, response size limit, or redirect controls. An unauthenticated attacker can therefore force the authorization server to issue outbound requests to internal services, loopback addresses, or cloud metadata endpoints (blind SSRF). The fix constrains remote URI fetching so these parameters cannot target arbitrary internal hosts.
You are affected if you are using a version that falls within the vulnerable range and expose the OAuth authorization endpoint or OpenID Connect dynamic client registration.
boruta is vulnerable to Server-Side Request Forgery (SSRF) in versions 2.3.2 - 2.3.6.
Upgrade the boruta library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.