OAUTH2_TOKEN_REUSE_DETECTION_FAILURE security auth_error ai_generated true

OAuth2令牌重用检测失败允许重放攻击

OAuth2 token reuse detection failure allows replay attack

ID: security/oauth2-token-reuse-detection-failure-allows-replay-attack

其他格式: JSON · Markdown 中文 · English
89%修复率
81%置信度
1证据数
2024-02-14首次发现

版本兼容性

版本状态引入弃用备注
OAuth2.0 active
Spring Security 5.6+ active
Keycloak 22.0.0 active
Auth0 2024.02 active

根因分析

当授权服务器未跟踪授权代码或访问令牌是否已被使用时,攻击者可以重放捕获的令牌以获得未经授权的访问。

English

When the authorization server does not track whether an authorization code or access token has already been used, an attacker can replay a captured token to gain unauthorized access.

generic

官方文档

https://datatracker.ietf.org/doc/html/rfc6749#section-10.5

解决方案

  1. Implement token reuse detection on the authorization server: store a flag or timestamp for each authorization code and access token, and reject requests that use an already-used code or token. Example in Spring Security: configure OAuth2AuthorizationService with a persistent store that marks codes as used.
  2. Use short-lived authorization codes (e.g., 1 minute) and access tokens (e.g., 5 minutes) combined with reuse detection to minimize the replay window.
  3. Implement token binding (e.g., via DPoP or mTLS) to tie tokens to a specific client, preventing replay from other clients.

无效尝试

常见但无效的做法:

  1. 70% 失败

    Relying on short token lifetimes (e.g., 5 minutes) does not prevent replay within that window; an attacker can replay the token immediately after capture.

  2. 60% 失败

    Using a nonce in the request is insufficient if the authorization server does not track nonces per token; an attacker can reuse the same nonce.

  3. 50% 失败

    Encrypting the token does not prevent replay because the attacker can still send the same encrypted token.