CyberRota Analysis
AI-GeneratedThe `vk-app` backend of Python Social Auth prior to version 5.0.0 is vulnerable due to its failure to verify callback signatures when the `auth_key` parameter is omitted, allowing attackers to manipulate callback data and impersonate arbitrary VK users. This poses a significant risk for applications relying on this backend for social authentication, as it can lead to unauthorized access and identity spoofing. Developers and organizations utilizing this authentication mechanism should prioritize upgrading to version 5.0.0 or later to mitigate this vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as `viewer_id`, `access_token`, `api_id`, and `api_result`, potentially allowing authentication as an arbitrary VK user ID. The issue affects only applications using the `vk-app` backend. The issue has been fixed in version 5.0.0 by requiring `auth_key` to be present and valid before callback data is trusted.