Описание
A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java of the component OAuth2/OIDC. Performing a manipulation of the argument redirect_uri results in open redirect. It is possible to initiate the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.
A flaw was found in Trino's OAuth2/OIDC component. A remote attacker can exploit this vulnerability by manipulating the redirect_uri argument, leading to an open redirect. This could allow an attacker to redirect users to malicious websites, potentially enabling phishing attacks or credential theft.
Отчет
Red Hat products that include the Trino Python client library (PyPI trino) are not affected by this vulnerability. The flaw exists exclusively in the Trino Java server's OAuth2/OIDC authentication handler (ExternalUriInfo.java in core/trino-main), which constructs OAuth redirect URIs from HTTP request headers without proper validation. The Python client library does not contain this server-side code.
Ссылки на источники
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS3
Связанные уязвимости
A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java of the component OAuth2/OIDC. Performing a manipulation of the argument redirect_uri results in open redirect. It is possible to initiate the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java of the component OAuth2/OIDC. Performing a manipulation of the argument redirect_uri results in open redirect. It is possible to initiate the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.
EPSS
4.3 Medium
CVSS3