CVE-2017-1000070: Input Validation
Published Jul 13, 2017
·Updated
The Bitly oauth2proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused by improper input validation and a violation of RFC-6819
Affected Software
2 affected componentsFixes available
go/github.com/bitly/oauth2_proxy<2.2.0
2.2.0
Oauth2 Proxy Project Oauth2 Proxy<=2.1
Remediation
Patch Available
Event History
Jul 13, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Dec 20, 2021
Advisory Published
06:04 PM
Frequently Asked Questions
1
What is the severity of CVE-2017-1000070?
CVE-2017-1000070 has a medium severity rating due to its potential for exploitation via open redirect.
2
How do I fix CVE-2017-1000070?
To fix CVE-2017-1000070, upgrade to oauth2_proxy version 2.2.0 or later.
3
What software is affected by CVE-2017-1000070?
CVE-2017-1000070 affects oauth2_proxy versions 2.1 and earlier.
4
What causes CVE-2017-1000070?
CVE-2017-1000070 is caused by improper input validation leading to an open redirect vulnerability.
5
What are the implications of CVE-2017-1000070?
The implications of CVE-2017-1000070 include potential phishing attacks and unauthorized access due to redirect issues.