Description
Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.
Remediation
References
https://github.com/GluuFederation/oxAuth/releases/tag/4.4.1
https://gluu.org/gluu-4-4-1/
Related Vulnerabilities
CVE-2018-17244 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2022-45396 Vulnerability in maven package com.thalesgroup.hudson.plugins:sourcemonitor
CVE-2022-24771 Vulnerability in npm package node-forge
CVE-2021-4305 Vulnerability in npm package robots-txt-guard
CVE-2018-1262 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-uaa