Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jm34-xm8m-w958

Опубликовано: 20 дек. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Open Redirect in oauth2_proxy

The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused by improper input validation and a violation of RFC-6819

Пакеты

Наименование

github.com/bitly/oauth2_proxy

go
Затронутые версииВерсия исправления

< 2.2.0

2.2.0

EPSS

Процентиль: 39%
0.00178
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 6.1
nvd
больше 8 лет назад

The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused by improper input validation and a violation of RFC-6819

EPSS

Процентиль: 39%
0.00178
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601