@feathersjs/authentication-oauth is vulnerable to Open Redirect
55
Medium Risk
Affected versions of this package are vulnerable to open redirect due to insufficient validation of the redirect query parameter. The application does not properly restrict certain redirect patterns, allowing crafted values to point to external locations. An attacker could exploit this behavior to redirect users to attacker-controlled sites after authentication.
You are affected if you are using a version that falls within the vulnerable range and SAML IdP-initiated single sign-on is enabled.
@feathersjs/authentication-oauth is vulnerable to Open Redirect in versions 4.0.0 - 4.5.18.
Upgrade the @feathersjs/authentication-oauth library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant