OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malicious redirect uri can cause denial of service. An attacker can also leverage usage of `uri_validate` functions depending where it is used. OAuthLib applications using OAuth2.0 provider support or use directly `uri_validate` are affected by this issue. Version 3.2.1 contains a patch. There are no known workarounds.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-09-09T00:00:00

Updated: 2024-08-03T09:52:00.509Z

Reserved: 2022-07-15T00:00:00

Link: CVE-2022-36087

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-09-09T21:15:08.477

Modified: 2023-11-07T03:49:32.883

Link: CVE-2022-36087

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-09-09T00:00:00Z

Links: CVE-2022-36087 - Bugzilla