MEDIUM6.1
GHSA-jm34-xm8m-w958
Open Redirect in oauth2_proxy
Quick fix
GHSA-jm34-xm8m-w958 — github.com/bitly/oauth2_proxy: upgrade to the fixed version with the command below.
go get github.com/bitly/oauth2_proxy@v2.2.0Details
The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused by improper input validation and a violation of RFC-6819
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/bitly/oauth2_proxy
Introduced in:
0Fixed in: 2.2.0Fix
go get github.com/bitly/oauth2_proxy@v2.2.0References
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000070[ADVISORY]
- https://github.com/bitly/oauth2_proxy/issues/228[WEB]
- https://github.com/bitly/oauth2_proxy/pull/359[WEB]
- https://github.com/bitly/oauth2_proxy/commit/289a6ccf463a425c7606178c510fc5eeb9c8b050[WEB]
- https://tools.ietf.org/html/rfc6819#section-5.2.3.5[WEB]
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-1000070[WEB]