VDB
Sign up
HIGH8.1

GHSA-44p5-3m5g-vfhj

SAP Approuter has an Open Redirect vulnerability

Quick fix

GHSA-44p5-3m5g-vfhj — @sap/approuter: upgrade to the fixed version with the command below.

npm install @sap/approuter@21.2.0

Details

SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@sap/approuter
Introduced in: 0Fixed in: 21.2.0
Fixnpm install @sap/approuter@21.2.0

References