Junglewise Threat Intelligence

CVE-2022-3145: Okta OIDC Middleware open redirect vulnerability

CVE-2022-3145 · Severity: low · CVSS 3.1 · Published 2023-01-09

Vendors: npm, Okta.

Executive brief

Okta OIDC Middleware is a library that enables single sign-on (SSO) authentication for web applications. An open redirect flaw allows attackers to craft malicious login URLs that, after a user successfully authenticates, redirect them to an attacker-controlled website instead of the legitimate application. This undermines trust in the authentication flow and can be used for phishing or credential harvesting attacks.

Technical details

This is a CWE-601 (URL Redirection to Untrusted Site) vulnerability in the Okta OIDC Middleware authentication library. The root cause is that the middleware does not properly validate the redirect destination URL after a successful login, accepting user-controlled input that specifies where to send the user post-authentication. The attack requires no special privileges and is network-accessible, but does require user interaction (the victim must complete a login flow via a malicious link). An attacker can redirect authenticated users to arbitrary external sites, enabling phishing or social engineering. The vulnerability was fixed in version 5.0.0; all versions prior to 5.0.0 are affected. The fix is documented in commit 5d10b3c which implements validation to prevent open redirects.

Affected products

  • Okta @okta/oidc-middleware <5.0.0

Timeline

  • 2023-01-05: disclosed: Advisory published by Okta
  • 2022-09-01: patched: Fix committed in version 5.0.0 (commit 5d10b3c)
  • 2023-01-09: advisory: GHSA-58h4-9m7m-j9m4 published

References