Open Redirect Affecting express-openid-connect package, versions <2.7.2
Threat Intelligence
EPSS
0.06% (28th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-EXPRESSOPENIDCONNECT-2438394
- published 1 Apr 2022
- disclosed 31 Mar 2022
- credit Unknown
Introduced: 31 Mar 2022
CVE-2022-24794 Open this link in a new tabHow to fix?
Upgrade express-openid-connect
to version 2.7.2 or higher.
Overview
express-openid-connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect.
Affected versions of this package are vulnerable to Open Redirect when the middleware is applied to a catch all route.
If all routes under example.com
are protected with the requiresAuth middleware, a visit to http://example.com//google.com
will be redirected to google.com
after login because the original url reported by the Express framework is not properly sanitised.
References
CVSS Scores
version 3.1