Security Advisory - Duende IdentityServer Pushed Authorization Requests (GHSA-mxv6-xwqj-ww2p)

Two blue circles

A high-severity vulnerability (CVSS 8.2) has been identified in the Pushed Authorization Requests (PAR) endpoint of Duende IdentityServer. The endpoint performs insufficient validation of pushed requests, resulting in three related weaknesses:

  • Requests are not bound to the authenticated client. A client can push an authorization request on behalf of a different client. Under default options this enables authorization request forgery within the victim client's registered redirect URIs. All deployments with the PAR endpoint enabled are affected, as it is enabled by default.
  • Implicit-only clients are treated as confidential without authenticating. Only exploitable when the non-default option AllowUnregisteredPushedRedirectUris is enabled. An unauthenticated attacker can push a request with an arbitrary redirect_uri, leading to token theft.
  • Unregistered pushed redirect URIs are not scheme-restricted. Also requires AllowUnregisteredPushedRedirectUris, and can result in cross-site scripting on the IdentityServer origin in browsers that do not enforce CSP Level 2.

Full details and affected versions: https://github.com/DuendeSoftware/products/security/advisories/GHSA-mxv6-xwqj-ww2p

Recommended action

We strongly recommend updating to the latest patched release on your current 7.x or 8.x branch.

If you cannot upgrade immediately, the following workarounds reduce your exposure:

  • Ensure options.PushedAuthorization.AllowUnregisteredPushedRedirectUris is set to false (the default). This removes weaknesses 2 and 3.
  • If no clients depend on PAR, the endpoint can be disabled with options.Endpoints.EnablePushedAuthorizationEndpoint = false. Note this will break any client configured with RequirePushedAuthorization = true.
  • If PAR must remain enabled with less-trusted clients, a custom IPushedAuthorizationRequestValidator can reject requests whose client_id does not match the authenticated client.

The full details for this advisory are available on GitHub.

Related Articles