BIT-oauth2-proxy-2021-21291

    Dashboard / Vulnerabilities / BIT-oauth2-proxy-2021-21291

    BIT-oauth2-proxy-2021-21291

    Published: 6 Mar 2024Last Modified: 8 Sept 2026

    Summary: Subdomain checking of whitelisted domains could allow unintended redirects

    Details: OAuth2 Proxy is an open-source reverse proxy and static file server that provides authentication using Providers (Google, GitHub, and others) to validate accounts by email, domain or group. In OAuth2 Proxy before version 7.0.0, for users that use the whitelist domain feature, a domain that ended in a similar way to the intended domain could have been allowed as a redirect. For example, if a whitelist domain was configured for ".example.com", the intention is that subdomains of example.com are allowed. Instead, "example.com" and "badexample.com" could also match. This is fixed in version 7.0.0 onwards. As a workaround, one can disable the whitelist domain feature and run separate OAuth2 Proxy instances for each subdomain.

    Affected packages

    Package

    Name: oauth2-proxy

    Purl: pkg:bitnami/oauth2-proxy

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -7.0.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    BIT-oauth2-proxy-2021-21291 | CVE-DB