Description
Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.
Remediation
References
https://github.com/GluuFederation/oxAuth/releases/tag/4.4.1
https://gluu.org/gluu-4-4-1/
Related Vulnerabilities
CVE-2017-16129 Vulnerability in maven package org.webjars.bower:superagent
CVE-2020-28052 Vulnerability in maven package org.bouncycastle:bcprov-ext-jdk14
CVE-2018-3735 Vulnerability in npm package bracket-template
CVE-2023-22665 Vulnerability in maven package org.apache.jena:jena-arq
CVE-2021-4245 Vulnerability in maven package org.webjars.npm:rfc6902