Impact
An open redirect vulnerability allowed attackers to exploit the redirect_uri query parameter to redirect a user from the authentication portal to an external website.
This vulnerability allows advanced phishing attacks. Token stealing is already mitigated.
Patches
#212
Workarounds
Enforce redirect_uri in your providers.
References
#212
Impact
An open redirect vulnerability allowed attackers to exploit the redirect_uri query parameter to redirect a user from the authentication portal to an external website.
This vulnerability allows advanced phishing attacks. Token stealing is already mitigated.
Patches
#212
Workarounds
Enforce redirect_uri in your providers.
References
#212