Executive brief
A vulnerability exists in a Perl library used by web applications to handle OAuth 2.0 logins. The software fails to verify that a login attempt was actually started by the user currently in the session. This allows an attacker to trick a victim into linking the attacker's social media or provider account to the victim's application account, potentially giving the attacker permanent access to the victim's data.
Technical details
The Dancer2::Plugin::Auth::OAuth::Provider library fails to implement the OAuth 2.0 'state' parameter, a critical security feature defined in RFC 6749. The 'authentication_url' method generates authorization redirects without a state value, and the 'callback' method processes authorization codes without verifying that the response corresponds to a request initiated within the same session. An attacker can exploit this by initiating an OAuth flow with their own credentials and tricking a victim into clicking the resulting callback URL. This results in the attacker's identity being associated with the victim's session or account. The issue is fixed in version 0.23, which introduces CSPRNG-backed state token generation and validation.
Affected products
- BIAFRA Dancer2::Plugin::Auth::OAuth::Provider before 0.23
Timeline
- 2026-06-22: patched: Fix committed to GitHub repository
- 2026-07-04: advisory: CVE published to NVD