The Server.verify_request function in SimpleGeo python-oauth2 does not check the nonce, which allows remote attackers to perform replay attacks via a signed URL. The vulnerability does not appear to be patched according to the following discussion.
{
"cwe_ids": [
"CWE-347"
],
"github_reviewed_at": "2024-02-23T21:12:22Z",
"github_reviewed": true,
"severity": "HIGH",
"nvd_published_at": "2014-05-20T14:55:00Z"
}