VDB
Sign up
MEDIUM6.1

GHSA-jm34-xm8m-w958

Open Redirect in oauth2_proxy

Quick fix

GHSA-jm34-xm8m-w958 — github.com/bitly/oauth2_proxy: upgrade to the fixed version with the command below.

go get github.com/bitly/oauth2_proxy@v2.2.0

Details

The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused by improper input validation and a violation of RFC-6819

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/bitly/oauth2_proxy
Introduced in: 0Fixed in: 2.2.0
Fixgo get github.com/bitly/oauth2_proxy@v2.2.0

References