Profile Vulnerability

Severity [Critical]

Description

During the OAuth process, IdP server will return user-related information, like user id and email address. The vulnerability is caused by the incorrect implementations in the RP app/ server, where the RP server utilizes the improper parameter from IdP to authenticate the user. The failure to return correct identity proof by the RP app and the improper verification of the credential by the RP server are two types of common mistakes made by RPs.

Fig. 1
Fig. 2
Fig. 3

Impact

This vulnerability enables an attacker to log into RP App as the victim by leveraging the victim’s public user profile only.

Solution

Fig. 5

Reference

[1] Yang, Ronghai, Wing Cheong Lau, and Shangcheng Shi. "Breaking and Fixing Mobile App Authentication with OAuth2. 0-based Protocols." International Conference on Applied Cryptography and Network Security. Springer, Cham, 2017.