OAUTH2_REDIRECT_URI_MISMATCH security auth_error ai_generated true

OAuth2 redirect_uri mismatch allows callback interception

ID: security/oauth2-redirect-uri-mismatch-allows-callback-interception

Also available as: JSON · Markdown · 中文
92%Fix Rate
86%Confidence
1Evidence
2023-11-20First Seen

Version Compatibility

VersionStatusIntroducedDeprecatedNotes
OAuth2.0 active
Spring Security 5.6+ active
Keycloak 21.0.0 active
Okta 2023.09.0 active

Root Cause

When the redirect_uri in an OAuth2 authorization request does not match the registered callback URL, an attacker can intercept the authorization code by using a different redirect URI that they control.

generic

中文

当OAuth2授权请求中的redirect_uri与注册的回调URL不匹配时,攻击者可以通过使用他们控制的不同重定向URI来拦截授权代码。

Official Documentation

https://datatracker.ietf.org/doc/html/rfc6749#section-3.1.2

Workarounds

  1. 95% success Register exact redirect URIs on the authorization server (e.g., https://myapp.com/callback) and validate that the request's redirect_uri matches exactly, including path and query parameters. Example in Keycloak: in client settings, set 'Valid Redirect URIs' to 'https://myapp.com/callback' without wildcards.
    Register exact redirect URIs on the authorization server (e.g., https://myapp.com/callback) and validate that the request's redirect_uri matches exactly, including path and query parameters. Example in Keycloak: in client settings, set 'Valid Redirect URIs' to 'https://myapp.com/callback' without wildcards.
  2. 90% success Implement strict redirect URI validation on the client side: compare the received redirect URI against a whitelist of allowed URIs before processing the authorization code.
    Implement strict redirect URI validation on the client side: compare the received redirect URI against a whitelist of allowed URIs before processing the authorization code.
  3. 88% success Use PKCE in combination with exact redirect URI matching to prevent interception even if the redirect URI is slightly different.
    Use PKCE in combination with exact redirect URI matching to prevent interception even if the redirect URI is slightly different.

中文步骤

  1. Register exact redirect URIs on the authorization server (e.g., https://myapp.com/callback) and validate that the request's redirect_uri matches exactly, including path and query parameters. Example in Keycloak: in client settings, set 'Valid Redirect URIs' to 'https://myapp.com/callback' without wildcards.
  2. Implement strict redirect URI validation on the client side: compare the received redirect URI against a whitelist of allowed URIs before processing the authorization code.
  3. Use PKCE in combination with exact redirect URI matching to prevent interception even if the redirect URI is slightly different.

Dead Ends

Common approaches that don't work:

  1. 75% fail

    Using a wildcard in the registered redirect URI (e.g., https://*.example.com) allows attackers to register a subdomain they control, intercepting the code.

  2. 65% fail

    Allowing redirect URIs with different paths but same host is insufficient because attackers can use a path they control (e.g., /attacker-callback).

  3. 60% fail

    Validating only the hostname but not the path or query parameters leaves the system vulnerable to path-based interception.