PT-2020-17845 · Oauth2 Proxy · Oauth2 Proxy
Joelspeed
·
Published
2020-06-29
·
Updated
2024-03-06
·
CVE-2020-4037
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
OAuth2 Proxy versions 5.1.1 through 5.9.x
Description
The issue allows users to provide a redirect address for the proxy to send the authenticated user to at the end of the authentication flow. This redirect URL is checked within the proxy and validated before redirecting the user to prevent malicious actors providing redirects to potentially harmful sites.
Recommendations
For OAuth2 Proxy versions 5.1.1 through 5.9.x, update to version 6.0.0 to resolve the issue.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oauth2 Proxy