Description
Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.
Remediation
References
https://github.com/GluuFederation/oxAuth/releases/tag/4.4.1
https://gluu.org/gluu-4-4-1/
Related Vulnerabilities
CVE-2022-0355 Vulnerability in npm package simple-get
CVE-2023-47324 Vulnerability in maven package org.silverpeas.core:silverpeas-core-api
CVE-2021-41182 Vulnerability in maven package org.webjars:jquery-ui
CVE-2020-1925 Vulnerability in maven package org.apache.olingo:odata-client-core
CVE-2020-2324 Vulnerability in maven package org.jenkins-ci.plugins:cvs