SimpleGeo python-oauth2 does not check the nonce allowing replay attacks
High severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Oct 7, 2024
Description
Published by the National Vulnerability Database
May 20, 2014
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Feb 23, 2024
Last updated
Oct 7, 2024
The Server.verify_request function in SimpleGeo python-oauth2 does not check the nonce, which allows remote attackers to perform replay attacks via a signed URL.
The vulnerability does not appear to be patched according to the following discussion.
References