Description
Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.
Remediation
References
https://github.com/GluuFederation/oxAuth/releases/tag/4.4.1
https://gluu.org/gluu-4-4-1/
Related Vulnerabilities
CVE-2019-1003091 Vulnerability in maven package com.soasta.jenkins:cloudtest
CVE-2020-19697 Vulnerability in maven package org.webjars.npm:editor.md
CVE-2021-42357 Vulnerability in maven package org.apache.knox:gateway-service-knoxsso
CVE-2021-37136 Vulnerability in maven package io.netty:netty-codec
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http-core