Executive brief
oauth2-server is a Node.js library used to implement OAuth 2.0 authorization servers. The library improperly validates the redirect_uri parameter, allowing attackers to craft malicious URIs that bypass validation checks and redirect users to arbitrary sites or inject malicious content. This could be exploited to steal authorization codes, access tokens, or perform phishing attacks against users of applications using this library.
Technical details
The vulnerability exists in the redirect_uri validation logic within oauth2-server versions up to 3.1.1. The library uses an incomplete regex pattern (/^[a-zA-Z][a-zA-Z0-9+.-]+:/) defined in lib/validator/is.js to validate URI schemes before redirecting users. This pattern fails to enforce the full URI structure specified in RFC 3986 and allows malformed URIs with XSS payloads to pass validation. An unauthenticated attacker can craft a malicious authorization request with a specially-crafted redirect_uri parameter containing fragments or other URI components that bypass the validation, resulting in an open redirect or reflected XSS. The attack requires no user authentication but does require user interaction (clicking a malicious authorization link). The vulnerability is network-accessible and affects all versions through 3.1.1.
Affected products
- oauthjs oauth2-server through 3.1.1
Timeline
- 2022-08-30: disclosed: Advisory published on GitHub Security Advisory Database
- 2020-07-16: other: Vulnerability reported to oauth2-server project as issue #637
References
- https://github.com/oauthjs/node-oauth2-server/issues/637
- https://github.com/oauthjs/node-oauth2-server
- https://github.com/oauthjs/node-oauth2-server/blob/91d2cbe70a0eddc53d72def96864e2de0fd41703/lib/grant-types/authorization-code-grant-type.js
- https://github.com/oauthjs/node-oauth2-server/blob/91d2cbe70a0eddc53d72def96864e2de0fd41703/lib/validator/is.js
- https://tools.ietf.org/html/rfc3986
- https://tools.ietf.org/html/rfc6749