CVE-2020-12283
CVE-2020-12283
Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/redirect.go, such as for the //foo//example.com substring.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://github.com/sourcegraph/sourcegraph/blob/master/CHANGELOG.mdhttps://github.com/sourcegraph/sourcegraph/commit/c0f48172e815c7f66471a38f0a06d1fc32a77a64https://github.com/sourcegraph/sourcegraph/compare/v3.15.0...v3.15.1https://github.com/sourcegraph/sourcegraph/pull/10167https://securitylab.github.com/advisories/GHSL-2020-085-sourcegraph