Description
An open redirect vulnerability exists in Okta OIDC Middleware prior to version 5.0.0 allowing an attacker to redirect a user to an arbitrary URL.
Remediation
References
https://github.com/okta/okta-oidc-middleware/security/advisories/GHSA-58h4-9m7m-j9m4
Related Vulnerabilities
CVE-2021-21421 Vulnerability in npm package node-etsy-client
CVE-2022-0639 Vulnerability in npm package url-parse
CVE-2020-27219 Vulnerability in maven package org.eclipse.hawkbit:hawkbit-update-server
CVE-2023-37263 Vulnerability in npm package @strapi/plugin-content-manager
CVE-2022-2421 Vulnerability in maven package org.webjars.npm:socket.io-parser