octo-sts/app

octo-sts/app

Releases17
Frequency1 month 2 weeks
Last Release
Stars363
A GitHub App that acts like a Security Token Service (STS) for the Github API

CVE History

CVEPublishedCVSS v3CVSS v2
8.6 HIGH

Octo-STS is a GitHub App that acts like a Security Token Service (STS) for the GitHub API. Octo-STS versions before v0.5.3 are vulnerable to unauthenticated SSRF by abusing fields in OpenID Connect tokens. Malicious tokens were shown to trigger internal network requests which could reflect error logs with sensitive information. Upgrade to v0.5.3 to resolve this issue. This version includes patch sets to sanitize input and redact logging.

3.7 LOW

octo-sts is a GitHub App that acts like a Security Token Service (STS) for the Github API. This vulnerability can spike the resource utilization of the STS service, and combined with a significant traffic volume could potentially lead to a denial of service. This vulnerability is fixed in 0.1.0