Description
Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.
Remediation
References
https://github.com/GluuFederation/oxAuth/releases/tag/4.4.1
https://gluu.org/gluu-4-4-1/
Related Vulnerabilities
CVE-2023-43794 Vulnerability in npm package nocodb
CVE-2021-46363 Vulnerability in maven package info.magnolia:magnolia-core
CVE-2020-17518 Vulnerability in maven package org.apache.flink:flink-runtime_2.11
CVE-2022-32114 Vulnerability in npm package @strapi/strapi
CVE-2018-12536 Vulnerability in maven package org.eclipse.jetty:jetty-util