Open Redirect in OAuth2 Proxy
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.9epss 1.3%
exploitation probability
1.3%top 31% of all CVEs
observed exploitation
nono source reports it
OAuth2 Proxy before 5.0 has an open redirect vulnerability. Authentication tokens could be silently harvested by an attacker. This has been patched in version 5.0.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L
Affected products
pusher · OAuth2 Proxy