-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability centers around improper redirect validation during OAuth2 login flow. The doFinishLogin method is the logical endpoint handling authentication completion where redirect parameter processing occurs. The getRedirectUrl helper would be involved in URL construction. Patches would have modified these to add validation (like checking for relative URLs), but in vulnerable versions they process the 'from' parameter without sufficient checks. These functions would appear in stack traces when processing malicious redirect parameters during authentication flows.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.openshift.jenkins:openshift-login | maven | < 1.1.0.230.v5d7030b | 1.1.0.230.v5d7030b |
Ongoing coverage of React2Shell