Executive brief
Okta OIDC Middleware is a library that enables single sign-on (SSO) authentication for web applications. An open redirect flaw allows attackers to craft malicious login URLs that, after a user successfully authenticates, redirect them to an attacker-controlled website instead of the legitimate application. This undermines trust in the authentication flow and can be used for phishing or credential harvesting attacks.
Technical details
This is a CWE-601 (URL Redirection to Untrusted Site) vulnerability in the Okta OIDC Middleware authentication library. The root cause is that the middleware does not properly validate the redirect destination URL after a successful login, accepting user-controlled input that specifies where to send the user post-authentication. The attack requires no special privileges and is network-accessible, but does require user interaction (the victim must complete a login flow via a malicious link). An attacker can redirect authenticated users to arbitrary external sites, enabling phishing or social engineering. The vulnerability was fixed in version 5.0.0; all versions prior to 5.0.0 are affected. The fix is documented in commit 5d10b3c which implements validation to prevent open redirects.
Affected products
- Okta @okta/oidc-middleware <5.0.0
Timeline
- 2023-01-05: disclosed: Advisory published by Okta
- 2022-09-01: patched: Fix committed in version 5.0.0 (commit 5d10b3c)
- 2023-01-09: advisory: GHSA-58h4-9m7m-j9m4 published