Описание
Gluu Oxauth before v4.4.1 vulnerable to Server-Side Request Forgery attacks via a crafted request_uri parameter
Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.
Пакеты
Наименование
org.gluu:oxauth-common
maven
Затронутые версииВерсия исправления
< 4.4.1
4.4.1
Связанные уязвимости
CVSS3: 9.8
nvd
больше 3 лет назад
Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.