Impact
When the OAuth discovery endpoints serve tenant‑specific values via a shared HTTP cache without a Vary header, a cached response from one tenant can be served to another tenant’s clients. This allows an attacker to route authorization codes and client secrets to the wrong tenant’s token endpoint and to validate tokens against the wrong key set, thereby bypassing tenant isolation and potentially exposing data or granting unauthorized access.
Affected Systems
The affected product is ash_authentication_oauth2_server versions 0.1.3 through just before 0.3.1.
Risk and Exploitability
The CVSS base score of 6.3 denotes medium severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, but the missing Vary header makes the flaw trivially exploitable whenever a shared cache sits in front of the server. Exposure is not yet reported in the CISA KEV catalog. Attackers can trigger the issue by requesting the OAuth discovery endpoints; no special authentication is required on the server side, and the cached response may serve cross‑tenant clients for up to one hour.
OpenCVE Enrichment