-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| @sap/approuter | npm | >= 2.6.1, < 16.7.2 | 16.7.2 |
The vulnerability (CWE-601) involves improper validation of redirect URIs during OAuth2 authorization code exchange. The first function likely failed to enforce strict redirect_uri validation, enabling open redirects. The second function's session-state validation weakness allowed session hijacking. Both align with the described attack vector (malicious payload injection during code exchange) and the patch version (16.7.2) suggests fixes in these areas. Confidence is high for the first function due to CWE mapping, and medium for the second due to inferred session management flaws.
KEV Misses 88% of Exploited CVEs- Get the report