GO-2022-0920None▾ SunlitIncorrect Authorization in ORY Oathkeeper in github.com/ory/oathkeeper
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
Incorrect Authorization in ORY Oathkeeper in github.com/ory/oathkeeper
github.com/ory/oathkeeper >= 0.38.0-beta.2, < 0.38.12-beta.1Upgrade to a patched release:
github.com/ory/oathkeeper 0.38.12-beta.1Connected by shared product, vendor, weakness, or advisory.
GHSA-vfvf-6gx5-mqv6High· 7.5Incorrect Authorization in ORY Oathkeeper
GHSA-qvp4-rpmr-xwrrHigh· 7.5Possible bypass of token claim validation when OAuth2 Introspection caching is enabled
CVE-2020-15223High· 8.0Ory fosite contains Improper Handling of Exceptional Conditions
CVE-2020-15222High· 8.1Token reuse in Ory fosite
CVE-2020-15233Medium· 6.1OAuth2 Redirect URL validity does not respect query parameters and character casing for loopback addresses
CVE-2020-5300Medium· 5.8Authentication Bypass in hydra