Skip to content

yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation

Low severity GitHub Reviewed Published Dec 16, 2023 in yiisoft/yii2-authclient • Updated Dec 22, 2023

Package

composer yiisoft/yii2-authclient (Composer)

Affected versions

<= 2.2.14

Patched versions

2.2.15

Description

Impact

What kind of vulnerability is it? Who is impacted?

Original Report:

The Oauth1/2 "state" and OpenID Connect "nonce" is vulnerable for a "timing attack" since it's compared via regular string
comparison (instead of Yii::$app->getSecurity()->compareString()).

Affected Code:

  1. OAuth 1 "state"

    https://github.com/yiisoft/yii2-authclient/blob/0d1c3880f4d79e20aa1d77c012650b54e69695ff/src/OAuth1.php#L158

  2. OAuth 2 "state"

    https://github.com/yiisoft/yii2-authclient/blob/0d1c3880f4d79e20aa1d77c012650b54e69695ff/src/OAuth2.php#L121

  3. OpenID Connect "nonce"

    https://github.com/yiisoft/yii2-authclient/blob/0d1c3880f4d79e20aa1d77c012650b54e69695ff/src/OpenIdConnect.php#L420

Patches

Has the problem been patched? What versions should users upgrade to?

TBD: Replace strcmp with Yii::$app->getSecurity()->compareString()).

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

not as far as I see.

References

Are there any links users can visit to find out more?

References

@samdark samdark published to yiisoft/yii2-authclient Dec 16, 2023
Published to the GitHub Advisory Database Dec 18, 2023
Reviewed Dec 18, 2023
Published by the National Vulnerability Database Dec 22, 2023
Last updated Dec 22, 2023

Severity

Low
0.0
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
Required
Scope
Changed
Confidentiality
None
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:N

Weaknesses

CVE ID

CVE-2023-50708

GHSA ID

GHSA-w8vh-p74j-x9xp

Credits

Checking history
See something to contribute? Suggest improvements for this vulnerability.