VDB
Sign up
MEDIUM5.9

GHSA-wqvh-63mv-9w92

@backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass

Quick fix

GHSA-wqvh-63mv-9w92 — @backstage/plugin-auth-backend: upgrade to the fixed version with the command below.

npm install @backstage/plugin-auth-backend@0.27.1

Details

### Impact

The experimental OIDC provider in `@backstage/plugin-auth-backend` is vulnerable to a redirect URI allowlist bypass. Instances that have enabled experimental Dynamic Client Registration or Client ID Metadata Documents and configured `allowedRedirectUriPatterns` are affected.

A specially crafted redirect URI can pass the allowlist validation while resolving to an attacker-controlled host. If a victim approves the resulting OAuth consent request, their authorization code is sent to the attacker, who can exchange it for a valid access token.

This requires victim interaction and that one of the experimental features is explicitly enabled, which is not the default.

### Patches

Upgrade to `@backstage/plugin-auth-backend` version 0.27.1 or later.

### Workarounds

Disable experimental Dynamic Client Registration and Client ID Metadata Documents features if they are not required.

### References

- [RFC 6749 Section 3.1.2 - Redirection Endpoint](https://datatracker.ietf.org/doc/html/rfc6749#section-3.1.2)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@backstage/plugin-auth-backend
Introduced in: 0Fixed in: 0.27.1
Fixnpm install @backstage/plugin-auth-backend@0.27.1

References