HIGHRubyGems →
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
Affected packages
- oauth2— 0.4.0 → 2.0.22
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- 0.27%
- EPSS percentile
- 18.8%
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 19%.
Sources
- https://github.com/ruby-oauth/oauth2/security/advisories/GHSA-pp92-crg2-gfv9
- https://github.com/ruby-oauth/oauth2/commit/0f0a474f1b38453e119e660c2daca742d4378ce9
- https://github.com/ruby-oauth/oauth2
- https://github.com/ruby-oauth/oauth2/releases/tag/v2.0.22
Structured record: https://osv.dev/vulnerability/GHSA-pp92-crg2-gfv9
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta