VDB
Sign up
HIGH7.2

GHSA-4rg6-fm25-gc34

oauth2-server through 3.1.1 vulnerable to Open Redirect

Details

In oauth2-server (aka node-oauth2-server) through 3.1.1, the value of the `redirect_uri` parameter received during the authorization and token request is checked against an incorrect URI pattern (`[a-zA-Z][a-zA-Z0-9+.-]+:`) before making a redirection. This allows a malicious client to pass an XSS payload through the redirect_uri parameter while making an authorization request. NOTE: this vulnerability is similar to CVE-2020-7741.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/oauth2-server
Introduced in: 0

No fixed version published yet for oauth2-server (npm). Pin to a known-safe version or switch to an alternative.

References