vulnerability

FreeBSD: VID-3003ba60-6cec-11eb-8815-040e3c1b8a02: oauth2-proxy -- domain whitelist could be used as redirect

Severity
6
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:N)
Published
Feb 12, 2021
Added
Feb 13, 2021
Modified
Dec 10, 2025

Description

The oauth2-proxy Team reports: In OAuth2 Proxy before version 7.0.0, for users that use the whitelist domain feature, a domain that ended in a similar way to the intended domain could have been allowed as a redirect.

Solution

freebsd-upgrade-package-oauth2-proxy

References

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.