-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The advisory explicitly lists these methods across multiple classes (DefaultIdentityServerInteractionService, ServerUrlExtensions, ReturnUrlParser, OidcReturnUrlParser) as having improper URL validation logic. All listed functions either: 1) Return non-null results for malicious URLs indicating trust, or 2) Return true from validation() checks for crafted URLs. The confidence is high because the functions are directly named in multiple authoritative sources (GitHub Security Advisories, NVD), and the vulnerability pattern matches CWE-601 (Open Redirect) through improper URL validation.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| IdentityServer4 | nuget | <= 4.1.2 |
Ongoing coverage of React2Shell