在 oauth-proxy 中发现了一个安全漏洞。该应用程序未能正确验证登录后的重定向目标参数( )。远程攻击者可以利用此漏洞,诱使用户点击一个精心构造的链接,导致用户在完成身份验证后被重定向到任意外部网站。这种开放重定向漏洞可被用于实施钓鱼攻击或窃取用户凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96577 | 7.1 HIGH | Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without a |
| CVE-2026-103754 | 5.9 MEDIUM | Ansible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows |
| CVE-2026-103641 | 5.5 MEDIUM | Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder |
No comments yet