OSV 1.4.0 · github-reviewed · 修改于 2022-01-26 04:49
发布时间
2022-01-22 07:52
GitHub 审查时间
2022-01-19 22:11
NVD 发布时间
2022-01-18 04:15
源文件
advisories/github-reviewed/2022/01/GHSA-vv38-4xcj-q4rw/GHSA-vv38-4xcj-q4rw.json
When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing. A request that included a specially crafted request parameter could be used to redirect the user to a page controlled by an attacker. This URL would need to be presented to the user outside the normal request flow through a XSS or phishing campaign.