Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/redirect.go, such as for the //foo//example.com substring.
References
Configurations
History
No history.
Information
Published : 2020-04-30 05:15
Updated : 2024-11-21 04:59
NVD link : CVE-2020-12283
Mitre link : CVE-2020-12283
CVE.ORG link : CVE-2020-12283
JSON object : View
Products Affected
sourcegraph
- sourcegraph
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')