Medium severity5.9NVD Advisory· Published Jan 30, 2020· Updated Jun 17, 2026
CVE-2020-5233
CVE-2020-5233
Description
OAuth2 Proxy before 5.0 has an open redirect vulnerability. Authentication tokens could be silently harvested by an attacker. This has been patched in version 5.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/oauth2-proxy/oauth2-proxyGo | < 5.0.0 | 5.0.0 |
Affected products
4- osv-coords2 versions
< 5.0.0+ 1 more
- (no CPE)range: < 5.0.0
- (no CPE)range: < 5.0.0
- Range: < 5.0.0
- cpe:2.3:a:oauth2_proxy_project:oauth2_proxy:*:*:*:*:*:*:*:*Range: <5.0.0
Patches
Vulnerability mechanics
References
9- github.com/pusher/oauth2_proxy/commit/a316f8a06f3c0ca2b5fc5fa18a91781b313607b2nvdPatchThird Party Advisory
- github.com/pusher/oauth2_proxy/security/advisories/GHSA-qqxw-m5fj-f7gvnvdExploitPatchThird Party Advisory
- github.com/advisories/GHSA-qqxw-m5fj-f7gvghsaADVISORY
- github.com/pusher/oauth2_proxy/releases/tag/v5.0.0nvdRelease NotesThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2020-5233ghsaADVISORY
- blog.detectify.com/2019/05/16/the-real-impact-of-an-open-redirectghsaWEB
- github.com/oauth2-proxy/oauth2-proxy/security/advisories/GHSA-qqxw-m5fj-f7gvghsaWEB
- github.com/oauth2-proxy/oauth2_proxy/commit/a316f8a06f3c0ca2b5fc5fa18a91781b313607b2ghsaWEB
- github.com/oauth2-proxy/oauth2_proxy/releases/tag/v5.0.0ghsaWEB
News mentions
0No linked articles in our index yet.