HIGH8.8
GHSA-rrm8-32g4-w8m3
Cross-site Request Forgery (CSRF)
Quick fix
GHSA-rrm8-32g4-w8m3 — github.com/bitly/oauth2_proxy: upgrade to the fixed version with the command below.
go get github.com/bitly/oauth2_proxy@v2.2.0Details
CSRF in Bitly oauth2_proxy 2.1 during authentication flow
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/bitly/oauth2_proxy
Introduced in:
0Fixed in: 2.2.0Fix
go get github.com/bitly/oauth2_proxy@v2.2.0