AI analysis
Loom for AWS before 1.7.0 has a server-side request forgery flaw in OAuth2 discovery handling (CWE-918), with a related risk of sensitive data being sent outward (CWE-201). An authenticated remote user triggers it by supplying a crafted discovery-document address when registering a tool server or remote agent configured for delegated authentication; CVSS 4.0 rates required privileges as high (8.2). The application may then issue requests to arbitrary internal network locations, and the attacker may obtain another user's access token for the same deployment. Impact is confidentiality of tokens and internal services; integrity and availability are not described as affected. No public proof of concept is known, and the issue is not in CISA's Known Exploited Vulnerabilities catalog.
What to do: Upgrade Loom for AWS to version 1.7.0 or later. Until then, limit who can register tool servers and remote agents that use delegated authentication, and review existing registrations and outbound logs for unexpected discovery-document addresses or requests to internal network locations. Rotate access tokens that may have been exposed.
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the access token of another user of the deployment and to cause the application to issue requests to arbitrary internal network locations, via a crafted discovery document address supplied when registering a tool server or remote agent configured for delegated authentication. To remediate this issue, users should upgrade to version 1.7.0 or later.