VulnerabilityModified
CVE-2020-5233
OAuth2 Proxy before 5.0 has an open redirect vulnerability.
MEDIUM 6.1EPSS 1.30%
Does this matter?
Lower severity and a low EPSS score (1.30%). Track it; it rarely justifies an emergency change on its own.
Description
OAuth2 Proxy before 5.0 has an open redirect vulnerability. Authentication tokens could be silently harvested by an attacker. This has been patched in version 5.0.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.30% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- oauth2 proxy project/oauth2 proxy
- Source
- security-advisories@github.com
References
- https://github.com/pusher/oauth2_proxy/commit/a316f8a06f3c0ca2b5fc5fa18a91781b313607b2Patch, Third Party Advisory
- https://github.com/pusher/oauth2_proxy/releases/tag/v5.0.0Release Notes, Third Party Advisory
- https://github.com/pusher/oauth2_proxy/security/advisories/GHSA-qqxw-m5fj-f7gvExploit, Patch, Third Party Advisory
- https://github.com/pusher/oauth2_proxy/commit/a316f8a06f3c0ca2b5fc5fa18a91781b313607b2Patch, Third Party Advisory
- https://github.com/pusher/oauth2_proxy/releases/tag/v5.0.0Release Notes, Third Party Advisory
- https://github.com/pusher/oauth2_proxy/security/advisories/GHSA-qqxw-m5fj-f7gvExploit, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.