Impact
Affected is an unknown function in Trino's OAuth2/OIDC component, specifically in ExternalUriInfo.java. Manipulating the redirect_uri parameter allows an attacker to cause the server to redirect users to an arbitrary external URL. This open redirect flaw permits remote exploitation, enabling phishing campaigns, session hijacking, or delivery of malicious content without needing to compromise the Trino instance itself.
Affected Systems
The vulnerability impacts Trino 481. The affected product is Trino from Trinodb. No patch or fix is currently available; the project has not responded to the issue at the time of reporting. Administrators should immediately verify whether they are running an affected release and assess their exposure.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. With an EPSS score of less than 1% and no listing in the CISA KEV catalog, the likelihood of widespread exploitation is low at present. However, the remote nature of the attack and the potential to trick users into visiting malicious sites make the risk still relevant, especially in environments where Trino serves authenticated users who might be targeted.
OpenCVE Enrichment