First published: Thu Jan 12 2023(Updated: )
An open redirect vulnerability exists in Okta OIDC Middleware prior to version 5.0.0 allowing an attacker to redirect a user to an arbitrary URL.
Credit: psirt@okta.com
Affected Software | Affected Version | How to fix |
---|---|---|
Okta Oidc Middleware | <5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3145 is an open redirect vulnerability in Okta OIDC Middleware prior to version 5.0.0.
CVE-2022-3145 allows an attacker to redirect a user to an arbitrary URL.
CVE-2022-3145 has a severity rating of medium with a CVSS score of 4.7.
To fix CVE-2022-3145, update Okta OIDC Middleware to version 5.0.0 or later.
You can find more information about CVE-2022-3145 in the Okta OIDC Middleware security advisory on GitHub: [link](https://github.com/okta/okta-oidc-middleware/security/advisories/GHSA-58h4-9m7m-j9m4)