Logto Server-Side Request Forgery via OIDC SSO Connector Issuer URL
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.2epss 0.3%
exploitation probability
0.3%top 81% of all CVEs
observed exploitation
nono source reports it
Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter. Tenant administrators with Management API credentials can supply arbitrary internal URLs to trigger HTTP GET requests to private network services, with response content returned in API responses.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Affected products
logto-io · logtoReferences
https://github.com/logto-io/logtohttps://github.com/logto-io/logto/blob/v1.42.0/packages/core/src/sso/OidcConnector/utils.tshttps://github.com/logto-io/logto/commit/16f4b2e732d5114ac98646c9370ec6ab61d6ed26https://github.com/logto-io/logto/issues/9465https://www.vulncheck.com/advisories/logto-server-side-request-forgery-via-oidc-sso-connector-issuer-url