
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (GHSA-mjcr-rqjg-rhg3) was identified in datasette-indieauth version 1.0, a Python package for IndieAuth authentication. The issue was discovered and published on November 19, 2020, and involves a critical security flaw where the implementation incorrectly trusts the 'me' field returned by the authorization server without proper verification (GitHub Advisory).
The vulnerability stems from a failure to verify that the final 'me' URL value returned by the authorization server belongs to the same domain as the initial value entered by the user. This implementation oversight relates to CWE-290 and was assigned a Critical severity rating. The issue was fixed in version 1.1 by implementing domain verification checks between the original and returned 'me' values (GitHub Commit).
The vulnerability allows a malicious user to sign in as any user with any IndieAuth identifier, effectively bypassing authentication controls. This security flaw could lead to unauthorized access and potential impersonation of legitimate users (GitHub Advisory).
The vulnerability is considered highly exploitable due to its critical severity rating and the straightforward nature of the authentication bypass. The flaw exists in the core authentication mechanism and requires no special conditions or complex exploitation techniques (GitHub Advisory).
There are no workarounds available for this vulnerability. Users must upgrade to version 1.1 immediately, which implements proper domain verification between the original and returned 'me' values. The patch ensures that the returned 'me' URL value belongs to the same domain as the initial user-entered value (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."