social-auth-core@4.0.3

Python social authentication made simple.

  • latest version

    5.2.0

  • latest non vulnerable version

  • first published

    9 years ago

  • latest version published

    1 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the social-auth-core package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Improper Validation of Integrity Check Value

    social-auth-core is a package that makes Python social authentication simple.

    Affected versions of this package are vulnerable to Improper Validation of Integrity Check Value via the SAML authentication backend (social_core/backends/saml.py), which fails to validate SAML responses against the originating AuthnRequest ID. An attacker can forge or replay a SAML response with a mismatched or absent InResponseTo field, bypassing the binding between the identity provider's response and the original authentication request, which can lead to account takeover or unauthorized account association.

    How to fix Improper Validation of Integrity Check Value?

    Upgrade social-auth-core to version 5.0.0 or higher.

    [,5.0.0)
    • H
    Authentication Bypass by Alternate Name

    social-auth-core is a package that makes Python social authentication simple.

    Affected versions of this package are vulnerable to Authentication Bypass by Alternate Name via the get_user_id method in the Vend OAuth2 backend (social_core/backends/vend.py), where user identifiers are scoped only to a shop-local numeric ID rather than being namespaced by the shop's domain_prefix. Because two different Vend shops can issue the same numeric user ID, an attacker who controls an account on one shop can authenticate as an unrelated user on a different shop that shares the same numeric ID, bypassing account isolation and gaining full access to that user's account.

    How to fix Authentication Bypass by Alternate Name?

    Upgrade social-auth-core to version 5.0.0 or higher.

    [,5.0.0)
    • M
    Cross-site Request Forgery (CSRF)

    social-auth-core is a package that makes Python social authentication simple.

    Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) via the LoginRadiusAuth backend in social_core/backends/loginradius.py, which sets REDIRECT_STATE = False and STATE_PARAMETER = False, disabling OAuth2 state parameter validation entirely. An attacker can perform a login CSRF attack by tricking a victim into completing an OAuth2 flow that the attacker initiated, allowing the attacker to associate the victim's browser session with an account the attacker controls.

    How to fix Cross-site Request Forgery (CSRF)?

    Upgrade social-auth-core to version 5.0.0 or higher.

    [,5.0.0)
    • C
    Improper Verification of Cryptographic Signature

    social-auth-core is a package that makes Python social authentication simple.

    Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature via the auth_complete method in the VKAppOAuth2 backend, where the auth_key signature is not required to be present in the callback payload. An attacker can submit a callback request without an auth_key value, bypassing signature verification entirely and authenticating as an arbitrary VK user.

    How to fix Improper Verification of Cryptographic Signature?

    Upgrade social-auth-core to version 5.0.0 or higher.

    [,5.0.0)
    • L
    Session Fixation

    social-auth-core is a package that makes Python social authentication simple.

    Affected versions of this package are vulnerable to Session Fixation via the partial pipeline resume mechanism in social_core/utils.py and social_core/actions.py. An attacker can resume another user's partial authentication pipeline token from a different session, bypassing session ownership checks and gaining unauthorized access to the authentication flow. This allows cross-session hijacking of in-progress authentication pipelines, potentially leading to account takeover or unauthorized identity linkage.

    How to fix Session Fixation?

    Upgrade social-auth-core to version 5.0.0 or higher.

    [,5.0.0)