Vulnerabilities > Oauth2 Proxy Project

DATE CVE VULNERABILITY TITLE RISK
2021-03-26 CVE-2021-21411 Incorrect Authorization vulnerability in Oauth2 Proxy Project Oauth2 Proxy 7.0.0/7.0.1
OAuth2-Proxy is an open source reverse proxy that provides authentication with Google, Github or other providers.
network
low complexity
oauth2-proxy-project CWE-863
5.5
2021-02-02 CVE-2021-21291 Open Redirect vulnerability in Oauth2 Proxy Project Oauth2 Proxy
OAuth2 Proxy is an open-source reverse proxy and static file server that provides authentication using Providers (Google, GitHub, and others) to validate accounts by email, domain or group.
network
low complexity
oauth2-proxy-project CWE-601
6.1
2020-06-29 CVE-2020-4037 Open Redirect vulnerability in Oauth2 Proxy Project Oauth2 Proxy 5.1.1
In OAuth2 Proxy from version 5.1.1 and less than version 6.0.0, users can provide a redirect address for the proxy to send the authenticated user to at the end of the authentication flow.
network
low complexity
oauth2-proxy-project CWE-601
5.4
2020-05-07 CVE-2020-11053 Open Redirect vulnerability in Oauth2 Proxy Project Oauth2 Proxy
In OAuth2 Proxy before 5.1.1, there is an open redirect vulnerability.
network
low complexity
oauth2-proxy-project CWE-601
6.1
2020-01-30 CVE-2020-5233 Open Redirect vulnerability in Oauth2 Proxy Project Oauth2 Proxy
OAuth2 Proxy before 5.0 has an open redirect vulnerability.
network
low complexity
oauth2-proxy-project CWE-601
6.1
2017-07-17 CVE-2017-1000070 Open Redirect vulnerability in Oauth2 Proxy Project Oauth2 Proxy
The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow.
network
low complexity
oauth2-proxy-project CWE-601
6.1
2017-07-17 CVE-2017-1000069 Cross-Site Request Forgery (CSRF) vulnerability in Oauth2 Proxy Project Oauth2 Proxy 2.1
CSRF in Bitly oauth2_proxy 2.1 during authentication flow
network
low complexity
oauth2-proxy-project CWE-352
8.8