Impact
Authorizer is an open‑source, self‑hostable authentication and authorization server. Prior to version 2.2.1, the /authorize endpoint accepts any redirect_uri without validating it against AllowedOrigins. When response_type=token or response_type=id_token, the server appends access_token, id_token, and refresh_token as query parameters and issues a 302 redirect to the attacker‑supplied URL. An unauthenticated attacker can obtain the required client_id from the public /graphql?query={meta{client_id}} endpoint. A partial fix was applied in v2.0.1 to other handlers (oauth_login, verify_email, magic_link_login, forgot_password, invite_members, oauth_callback) but /authorize was not included. Version 2.2.1 contains a more complete fix.
Affected Systems
The flaw affects authorizerdev:authorizer versions before 2.2.1. A partial mitigation was introduced in 2.0.1 for several can also /graphql endpoint.
Risk and Exploitability
The CVSS score of 9.3 categorises this issue as critical, and the exploit is straightforward: any remote user can supply a crafted redirect_uri and receive valid tokens. The EPSS score is < 1%, indicating a low but non‑zero probability of exploitation; however, the high severity and lack of a widespread patch still point to a significant risk. The vulnerability is not listed in CISA’s KEV catalog, but the potential for token hijacking and privilege escalation warrants immediate action.
OpenCVE Enrichment
Github GHSA