Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-phfx-x4q3-w99v

Опубликовано: 22 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.7

Описание

An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able to pass in a crafted redirect-url that bypasses validation, and consequently allows an attacker to redirect callbacks to a Top Level Domain controlled by the attacker.

An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able to pass in a crafted redirect-url that bypasses validation, and consequently allows an attacker to redirect callbacks to a Top Level Domain controlled by the attacker.

EPSS

Процентиль: 18%
0.00058
Низкий

8.7 High

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 8.7
nvd
около 2 лет назад

An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able to pass in a crafted redirect-url that bypasses validation, and consequently allows an attacker to redirect callbacks to a Top Level Domain controlled by the attacker.

CVSS3: 8.7
fstec
около 2 лет назад

Уязвимость конфигурации «Allow Subdomains» платформы авторизации OAuth2, позволяющая нарушителю обойти ограничения безопасности и перенаправить пользователя на произвольный URL-адрес

EPSS

Процентиль: 18%
0.00058
Низкий

8.7 High

CVSS3

Дефекты

CWE-601