← Zurück zur CVE-Suche

CVE-2026-12740

Plack::Middleware::OAuth

Beschreibung

Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. RequestTokenV2 builds the provider authorization redirect without issuing a state value, and AccessTokenV2 exchanges the callback code and registers the resulting token into the session (register_session) without verifying that the callback corresponds to an authorization request this session initiated. Any application that uses this middleware for OAuth 2.0 login is exposed to login cross-site request forgery: because the callback is not bound to the session that began the flow, an attacker who starts an authorization with their own provider account can deliver the resulting callback to a victim, causing the victim-s session to complete the attacker-s authorization and associating the attacker-s provider identity and access token with that session. Where the application persists this as an account link, the attacker may retain access to the victim-s account through their own provider credentials.

CVSS 8.1EPSS 0.172%Risiko 0.82
Quelle öffnen
Veröffentlicht
2026-07-04 18:16:28
Betroffene Versionen
<=0.10
Typ
Bibliothek
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N