ZeroHour

CVE-2020-5233

PoC
CVSS 3.1
6.1 medium
EPSS
1%p69
Published
()
Modified
Description

OAuth2 Proxy before 5.0 has an open redirect vulnerability. Authentication tokens could be silently harvested by an attacker. This has been patched in version 5.0.

Vendors
oauth2 proxy project
Products
oauth2 proxy
Weakness
CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.