PT-2025-4303 · Unknown · Guzzle Oauth Subscriber

Psyker156

·

Published

2025-01-06

·

Updated

2025-01-06

·

CVE-2025-21617

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Guzzle OAuth Subscriber versions prior to 0.8.1
Description The issue concerns the Guzzle OAuth Subscriber, which signs Guzzle requests using OAuth 1.0. Prior to version 0.8.1, the Nonce generation does not utilize sufficient entropy nor a cryptographically secure pseudorandom source. This can leave servers vulnerable to replay attacks when TLS is not used.
Recommendations For versions prior to 0.8.1, upgrade to version 0.8.1 or higher to resolve the issue. As a temporary workaround, consider using TLS to encrypt communications and minimize the risk of replay attacks. Restrict access to sensitive resources when TLS cannot be used, to reduce the potential impact of a replay attack.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-21617
GHSA-237R-R8M4-4Q88

Affected Products

Guzzle Oauth Subscriber