{"id":"GHSA-mjcr-rqjg-rhg3","aliases":[],"url":"https://o3.security/vulnerability/GHSA-mjcr-rqjg-rhg3","summary":"Implementation trusts the \"me\" field returned by the authorization server without verifying it","details":"### Impact\n\nA malicious user can sign in as a user with any IndieAuth identifier. This is because the implementation does not verify that the final `\"me\"` URL value returned by the authorization server belongs to the same domain as the initial value entered by the user.\n\n### Patches\n\nVersion 1.1 fixes this issue.\n\n### Workarounds\n\nThere is no workaround. Upgrade to 1.1 immediately.\n\n### References\n\n- [Security Considerations: Differing User Profile URLs](https://indieauth.spec.indieweb.org/#differing-user-profile-urls-li-1) in the IndieAuth specification.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* Open an issue in [simonw/datasette-indieauth](https://github.com/simonw/datasette-indieauth/issues)","published":"2020-11-24T21:21:04Z","modified":"2022-03-21T20:04:49Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"datasette-indieauth","fixedVersion":"1.1"}],"fix":{"url":"https://github.com/simonw/datasette-indieauth/commit/376c8804c6b0811852049229a24336fe5eb6a439","label":"simonw/datasette-indieauth@376c880"},"references":[{"type":"WEB","url":"https://github.com/simonw/datasette-indieauth/security/advisories/GHSA-mjcr-rqjg-rhg3"},{"type":"WEB","url":"https://github.com/simonw/datasette-indieauth/commit/376c8804c6b0811852049229a24336fe5eb6a439"},{"type":"PACKAGE","url":"https://github.com/simonw/datasette-indieauth"},{"type":"WEB","url":"https://pypi.org/project/datasette-indieauth"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2022-03-21T20:04:49Z"}}