Security Advisory - Duende IdentityServer Pushed Authorization Requests (GHSA-mxv6-xwqj-ww2p)
A high-severity vulnerability (CVSS 8.2) has been identified in the Pushed Authorization Requests (PAR) endpoint of Duende IdentityServer. The endpoint performs insufficient validation of pushed requests, resulting in three related weaknesses:
- Requests are not bound to the authenticated client. A client can push an authorization request on behalf of a different client. Under default options this enables authorization request forgery within the victim client's registered redirect URIs. All deployments with the PAR endpoint enabled are affected, as it is enabled by default.
- Implicit-only clients are treated as confidential without authenticating. Only exploitable when the non-default option
AllowUnregisteredPushedRedirectUrisis enabled. An unauthenticated attacker can push a request with an arbitraryredirect_uri, leading to token theft. - Unregistered pushed redirect URIs are not scheme-restricted. Also requires
AllowUnregisteredPushedRedirectUris, and can result in cross-site scripting on the IdentityServer origin in browsers that do not enforce CSP Level 2.
Full details and affected versions: https://github.com/DuendeSoftware/products/security/advisories/GHSA-mxv6-xwqj-ww2p
Recommended action
We strongly recommend updating to the latest patched release on your current 7.x or 8.x branch.
If you cannot upgrade immediately, the following workarounds reduce your exposure:
- Ensure
options.PushedAuthorization.AllowUnregisteredPushedRedirectUrisis set tofalse(the default). This removes weaknesses 2 and 3. - If no clients depend on PAR, the endpoint can be disabled with
options.Endpoints.EnablePushedAuthorizationEndpoint = false. Note this will break any client configured withRequirePushedAuthorization = true. - If PAR must remain enabled with less-trusted clients, a custom
IPushedAuthorizationRequestValidatorcan reject requests whoseclient_iddoes not match the authenticated client.
The full details for this advisory are available on GitHub.