Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Jehiah

#18211de 53,633
14.9CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2017-10776
8.8
2017-07-13
Bitly · Oauth2 Proxy · CVE-2017-1000069
**Name of the Vulnerable Software and Affected Versions** Bitly oauth2 proxy version 2.1 **Description** The issue concerns a CSRF problem during the authentication flow in the specified software. **Recommendations** For version 2.1, update to a newer version that contains a fix for this issue.
PT-2017-10777
6.1
2017-07-13
Bitly · Oauth2 Proxy · CVE-2017-1000070
**Name of the Vulnerable Software and Affected Versions** Bitly oauth2 proxy versions 2.1 and earlier **Description** The issue is related to an open redirect vulnerability that occurs during the start and termination of the 2-legged OAuth flow. This is caused by improper input validation and a violation of RFC-6819. **Recommendations** For versions 2.1 and earlier, update to a version that addresses the improper input validation issue to prevent open redirect vulnerabilities.