PT-2025-4303 · Unknown · Guzzle Oauth Subscriber
Psyker156
·
Published
2025-01-06
·
Updated
2025-01-06
·
CVE-2025-21617
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Guzzle OAuth Subscriber versions prior to 0.8.1
Description
The issue concerns the Guzzle OAuth Subscriber, which signs Guzzle requests using OAuth 1.0. Prior to version 0.8.1, the Nonce generation does not utilize sufficient entropy nor a cryptographically secure pseudorandom source. This can leave servers vulnerable to replay attacks when TLS is not used.
Recommendations
For versions prior to 0.8.1, upgrade to version 0.8.1 or higher to resolve the issue. As a temporary workaround, consider using TLS to encrypt communications and minimize the risk of replay attacks. Restrict access to sensitive resources when TLS cannot be used, to reduce the potential impact of a replay attack.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Guzzle Oauth Subscriber