Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jehiah

#18301of 53,624
14.9Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2017-10776
8.8
2017-07-13
Bitly · Oauth2 Proxy · CVE-2017-1000069
**Name of the Vulnerable Software and Affected Versions** Bitly oauth2 proxy version 2.1 **Description** The issue concerns a CSRF problem during the authentication flow in the specified software. **Recommendations** For version 2.1, update to a newer version that contains a fix for this issue.
PT-2017-10777
6.1
2017-07-13
Bitly · Oauth2 Proxy · CVE-2017-1000070
**Name of the Vulnerable Software and Affected Versions** Bitly oauth2 proxy versions 2.1 and earlier **Description** The issue is related to an open redirect vulnerability that occurs during the start and termination of the 2-legged OAuth flow. This is caused by improper input validation and a violation of RFC-6819. **Recommendations** For versions 2.1 and earlier, update to a version that addresses the improper input validation issue to prevent open redirect vulnerabilities.