VDB
Sign up
MEDIUM6.1

GHSA-grfp-q2mm-hfp6

Redirect URL matching ignores character casing

Quick fix

GHSA-grfp-q2mm-hfp6 — github.com/ory/fosite: upgrade to the fixed version with the command below.

go get github.com/ory/fosite@v0.34.1

Details

### Impact

Before version v0.34.1, the OAuth 2.0 Client's registered redirect URLs and the redirect URL provided at the OAuth2 Authorization Endpoint where compared using `strings.ToLower` while they should have been compared with a simple string match:

1. Registering a client with allowed redirect URL `https://example.com/callback` 2. Performing OAuth2 flow and requesting redirect URL `https://example.com/CALLBACK` 3. Instead of an error (invalid redirect URL), the browser is redirected to `https://example.com/CALLBACK` with a potentially successful OAuth2 response, depending on the state of the overall OAuth2 flow (the user might still deny the request for example).

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/ory/fosite
Introduced in: 0Fixed in: 0.34.1
Fixgo get github.com/ory/fosite@v0.34.1

References