Impact
The vulnerability is described as an open redirect in the oauth‑proxy middleware, inferred from the CVE title. The flaw allows users to receive redirect URLs that bypass normal validation checks, potentially leading attackers to lure users to malicious sites after authentication. The weakness is consistent with CWE‑601, indicating improper validation of redirect destinations and facilitating phishing or credential theft scenarios. Due to the lack of an official description, the precise mechanics and affected inputs are not fully detailed in the data provided.
Affected Systems
The affected component is the oauth‑proxy middleware. No vendor or product version details are supplied, so the scope of installations that might be impacted cannot be precisely determined from the current information.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through crafted post‑login redirect URLs that exploit the bypass of the original validation logic; exploitation would require that the target environment employs the vulnerable redirect logic in oauth‑proxy.
OpenCVE Enrichment