Description
OAuth2 Proxy before 5.0 has an open redirect vulnerability. Authentication tokens could be silently harvested by an attacker. This has been patched in version 5.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2572 | OAuth2 Proxy before 5.0 has an open redirect vulnerability. Authentication tokens could be silently harvested by an attacker. This has been patched in version 5.0. |
Github GHSA |
GHSA-qqxw-m5fj-f7gv | The pattern '/\domain.com' is not disallowed when redirecting, allowing for open redirect |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T08:22:09.082Z
Reserved: 2020-01-02T00:00:00.000Z
Link: CVE-2020-5233
No data.
Status : Modified
Published: 2020-01-30T19:15:11.883
Modified: 2024-11-21T05:33:43.813
Link: CVE-2020-5233
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA