Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19078

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 4.3

Описание

A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an authenticated user, redirects them to an attacker-controlled website. This could enable phishing attacks, potentially tricking users into revealing sensitive information.

Отчет

Red Hat has determined that this vulnerability is Low severity. The open redirect in the OAuth server's grant handler enables phishing by redirecting users to attacker-controlled origins after the consent prompt, but does not expose OAuth tokens, authorization codes, or session credentials. The authorization code is issued separately to the client's registered redirect_uri.

Меры по смягчению последствий

There is no mitigation for this flaw. However, the risk is limited as the vulnerability only enables phishing — no OAuth tokens, authorization codes, or session credentials are exposed through the redirect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/ose-oauth-server-rhel8Fix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-oauth-server-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2511975ose-oauth-server: oauth-server: Open redirect vulnerability enables phishing via unvalidated parameter.

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
5 дней назад

A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an authenticated user, redirects them to an attacker-controlled website. This could enable phishing attacks, potentially tricking users into revealing sensitive information.

CVSS3: 4.3
github
5 дней назад

A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an authenticated user, redirects them to an attacker-controlled website. This could enable phishing attacks, potentially tricking users into revealing sensitive information.

4.3 Medium

CVSS3