Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of...
Vulnerability Description
Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/redirect.go, such as for the //foo//example.com substring.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-12283
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/sourcegraph/sourcegraph/pull/10167
- https://github.com/sourcegraph/sourcegraph/compare/v3.15.0...v3.15.1
- https://github.com/sourcegraph/sourcegraph/commit/c0f48172e815c7f66471a38f0a06d1fc32a77a64
- https://github.com/sourcegraph/sourcegraph/blob/master/CHANGELOG.md
- https://securitylab.github.com/advisories/GHSL-2020-085-sourcegraph
More from sourcegraph
View All →Affected Vendor
sourcegraph
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.