6.1
CVE-2026-83589
- EPSS 0.19%
- Veröffentlicht 01.10.2026 09:17:43
- Zuletzt bearbeitet 07.10.2026 00:17:21
- Erkennungen
Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect
A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt
Red Hat OpenShift Container Platform 4.20
Default Statusaffected
Version
1790704224
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat OpenShift Container Platform 4.21
Default Statusaffected
Version
1790706478
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat OpenShift Container Platform 4.22
Default Statusaffected
Version
1790724885
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat OpenShift Container Platform 4
Default Statusaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.078 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
https://access.redhat.com/security/cve/CVE-2026-83589
https://bugzilla.redhat.com/show_bug.cgi?id=2518379
https://access.redhat.com/errata/RHSA-2026:74383
https://access.redhat.com/errata/RHSA-2026:74429
https://access.redhat.com/errata/RHSA-2026:74380