PT-2020-17845 · Oauth2 Proxy · Oauth2 Proxy

Joelspeed

·

Published

2020-06-29

·

Updated

2024-03-06

·

CVE-2020-4037

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions OAuth2 Proxy versions 5.1.1 through 5.9.x
Description The issue allows users to provide a redirect address for the proxy to send the authenticated user to at the end of the authentication flow. This redirect URL is checked within the proxy and validated before redirecting the user to prevent malicious actors providing redirects to potentially harmful sites.
Recommendations For OAuth2 Proxy versions 5.1.1 through 5.9.x, update to version 6.0.0 to resolve the issue.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

BIT-OAUTH2-PROXY-2020-4037
CVE-2020-4037
GHSA-5M6C-JP6F-2VCV

Affected Products

Oauth2 Proxy