CVE-2020-15223High· 8.0▾ TwilightOry fosite contains Improper Handling of Exceptional Conditions
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.6%
The TokenRevocationHandler ignores errors coming from the storage. This can lead to unexpected 200 status codes indicating successful revocation while the token is still valid. Whether an attacker can use this for her advantage depends on the ability to trigger errors in the store.
RFC 7009 states that a 503 HTTP code must be returned when the server has a problem.
github.com/ory/fosite < 0.34.0Upgrade to a patched release:
github.com/ory/fosite 0.34.0Connected by shared product, vendor, weakness, or advisory.
CVE-2020-15222High· 8.1Token reuse in Ory fosite
CVE-2020-15233Medium· 6.1OAuth2 Redirect URL validity does not respect query parameters and character casing for loopback addresses
GO-2022-0920NoneIncorrect Authorization in ORY Oathkeeper in github.com/ory/oathkeeper
GHSA-vfvf-6gx5-mqv6High· 7.5Incorrect Authorization in ORY Oathkeeper
GHSA-qvp4-rpmr-xwrrHigh· 7.5Possible bypass of token claim validation when OAuth2 Introspection caching is enabled
CVE-2020-5300Medium· 5.8Authentication Bypass in hydra