The logout endpoint /oauth/logout?redirect=url can be abused to redirect logged in users to arbitrary web pages. This vulnerability could be used in phishing attacks. Versions shipped with Red Hat Mobile Aplication Platform 4 are believed to be vulnerable.
References
| Link | Resource |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=1770276 | Issue Tracking Vendor Advisory |
Configurations
Information
Published : 2021-01-28 20:15
Updated : 2021-02-04 19:01
NVD link : CVE-2020-1723
Mitre link : CVE-2020-1723
JSON object : View
Products Affected
redhat
- mobile_application_platform
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
