Skip to content
This repository has been archived by the owner on Oct 20, 2024. It is now read-only.

Open redirection via redirect_uri

Moderate
babelouest published GHSA-37q6-q9w8-4pr4 Feb 12, 2024

Package

No package listed

Affected versions

<= 2.7.6

Patched versions

None

Description

Impact

Glewlwyd SSO server 2.x through 2.7.6 allows open redirection via redirect_uri. When processing a /auth request, the redirect_uri parameter isn't verified correctly.

Patches

6f2d4a6

Severity

Moderate

CVE ID

CVE-2024-25715

Weaknesses

No CWEs