Credential Disclosure

Severity [High]

Description

Access token is the identity proof issued by IdP so that anyone in possession of the access token can access the protected user resources hosted by IdP. Therefore, developers should prevent this access token from disclosure. The app secret is a confidential information, which is only shared between RP and IdP. The app secret allows IdP to determine the identity of the RP app. Code is also a confidential information, and is used to exchange access token. Developers should prevent access token, code, app secret from disclosure.

Impact

If the attacker can obtain the access token (or code), then he can harvest the victim’s resource hosted by IdP, and even log into RP app as the victim. If the attacker can obtain the app secret, he can pretend to be the vulnerable RP app.

Solution

If app secret is disclosed, developers should revoke the app secret immediately. Whenever possible, utilize HTTPS protocol to protect any OAuth-related traffic.

Reference

[1] Zhou, Yuchen, and David Evans. "SSOScan: automated testing of web applications for single sign-on vulnerabilities." 23rd USENIX Security Symposium (USENIX Security 14). 2014.

[2] Sun, San-Tsai, and Konstantin Beznosov. "The devil is in the (implementation) details: an empirical analysis of oauth sso systems." Proceedings of the 2012 ACM conference on Computer and communications security. ACM, 2012.