blob: 734666ead61550a33b1fd6c65ede74bd30cd53a1 [file] [log] [blame]
id: GO-2024-3228
modules:
- module: github.com/coder/coder
vulnerable_at: 0.27.3
- module: github.com/coder/coder/v2
versions:
- introduced: 2.3.1
- fixed: 2.14.4
- introduced: 2.15.0
- fixed: 2.15.3
- introduced: 2.16.0
- fixed: 2.16.1
vulnerable_at: 2.16.0
summary: |-
Coder vulnerable to post-auth URL redirection to untrusted site ('Open
Redirect') in github.com/coder/coder
ghsas:
- GHSA-wcx9-ccpj-hx3c
references:
- advisory: https://github.com/coder/coder/security/advisories/GHSA-wcx9-ccpj-hx3c
- fix: https://github.com/coder/coder/commit/69c1d981e3131e50d52b01f6a360abadaad699e6
source:
id: GHSA-wcx9-ccpj-hx3c
created: 2024-10-28T20:48:48.504970195Z
review_status: UNREVIEWED