PT-2025-18344 · Unknown · Workers-Oauth-Provider
Published
2025-05-01
·
Updated
2025-05-05
·
CVE-2025-4143
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
workers-oauth-provider (affected versions not specified)
Description
The OAuth implementation in workers-oauth-provider did not correctly validate that the
redirect uri was on the allowed list of redirect URIs for the given client registration. This could potentially allow an attacker to steal a victim's credentials to the same OAuth server and impersonate them, under certain circumstances. The attack requires the victim to have previously authorized with a server built on workers-oauth-provider and the attacker to trick the victim into visiting a malicious website. The OAuth server's authorized callback must be designed to auto-approve authorizations that appear to come from an OAuth client that the victim has authorized previously.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Workers-Oauth-Provider