Junglewise Threat Intelligence

CVE-2021-21291: GO-2022-0790 - Subdomain checking of whitelisted domains could allow unintended redirects in oauth2-proxy in github.com/oauth2-proxy/oauth2-proxy

CVE-2021-21291 · Severity: low · CVSS 3.1 · Published 2024-08-21

Technologies: github.com/oauth2-proxy/oauth2-proxy (Go), github.com/oauth2-proxy/oauth2-proxy/v7 (Go). Vendors: Go.

Executive brief

Subdomain checking of whitelisted domains could allow unintended redirects in oauth2-proxy in github.com/oauth2-proxy/oauth2-proxy

Affected products

  • Go github.com/oauth2-proxy/oauth2-proxy
  • Go github.com/oauth2-proxy/oauth2-proxy/v7

Related threats