PT-2020-17845 · Oauth2 Proxy · Oauth2 Proxy

·

CVE-2020-4037

·

Published

2020-06-29

·

Updated

2024-03-06

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions OAuth2 Proxy versions 5.1.1 through 5.9.x
Description The issue allows users to provide a redirect address for the proxy to send the authenticated user to at the end of the authentication flow. This redirect URL is checked within the proxy and validated before redirecting the user to prevent malicious actors providing redirects to potentially harmful sites.
Recommendations For OAuth2 Proxy versions 5.1.1 through 5.9.x, update to version 6.0.0 to resolve the issue.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-OAUTH2-PROXY-2020-4037
CVE-2020-4037
GHSA-5M6C-JP6F-2VCV

Affected Products

Oauth2 Proxy