Octo-STS is a GitHub App that acts like a Security Token Service (STS) for the GitHub API. Octo-STS versions before v0.5.3 are vulnerable to unauthenticated SSRF by abusing fields in OpenID Connect tokens. Malicious tokens were shown to trigger internal network requests which could reflect error logs with sensitive information. Upgrade to v0.5.3 to resolve this issue. This version includes patch sets to sanitize input and redact logging.
History

Fri, 27 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Jun 2025 17:00:00 +0000

Type Values Removed Values Added
Description Octo-STS is a GitHub App that acts like a Security Token Service (STS) for the GitHub API. Octo-STS versions before v0.5.3 are vulnerable to unauthenticated SSRF by abusing fields in OpenID Connect tokens. Malicious tokens were shown to trigger internal network requests which could reflect error logs with sensitive information. Upgrade to v0.5.3 to resolve this issue. This version includes patch sets to sanitize input and redact logging.
Title Octo-STS Vulnerable to Unauthenticated SSRF with HTTP Response Reflection in OIDC Flow
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-06-26T16:46:09.380Z

Updated: 2025-06-27T13:16:43.418Z

Reserved: 2025-06-17T02:28:39.717Z

Link: CVE-2025-52477

cve-icon Vulnrichment

Updated: 2025-06-27T13:16:40.829Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-26T17:15:30.897

Modified: 2025-06-26T18:57:43.670

Link: CVE-2025-52477

cve-icon Redhat

No data.