Executive brief
The pattern '/\domain.com' is not disallowed when redirecting, allowing for open redirect
Affected products
- Go github.com/oauth2-proxy/oauth2-proxy
Junglewise Threat Intelligence
CVE-2020-5233 · Severity: low · CVSS 3.1 · Published 2021-12-20
Technologies: github.com/oauth2-proxy/oauth2-proxy (Go). Vendors: Go.
The pattern '/\domain.com' is not disallowed when redirecting, allowing for open redirect