ASVS Issue #3353 — OAuth認可コードの有効時間短縮(10.4.3)
ASVS Issue #3353 — OAuth認可コード有効時間の短縮
概要
要件 10.4.3 におけるOAuth認可コードの最大有効時間を短縮する提案。
詳細
現在の 10.4.3:
- L1/L2: 最大10分
- L3: 最大1分
提案:
- L1/L2: 1分に短縮
- L3: 30秒に短縮
提案の根拠:
- OAuth 2.1 仕様検討 (oauth-wg/oauth-v2-1#230)
- ConsentFix 攻撃の説明 (PushSecurity)
- IETF OAuth WG のブラウザ交換に関する議論
セキュリティ影響
- カテゴリ: V10 OAuth and OIDC
- 重要度: High — 認可コード横取り攻撃の窓を縮小
- 攻撃シナリオ: 認可コードの中間者攻撃、ConsentFix 等
原文
Current 10.4.3 reads: Verify that the authorization code is short-lived. The maximum lifetime can be up to 10 minutes for L1 and L2 applications and up to 1 minute for L3 applications.
I think it would make sense to reduce this to 1 minutes / 30 seconds.