VYPR

NuGet package

identityserver4

pkg:nuget/identityserver4

Vulnerabilities (1)

  • CVE-2024-39694MedJul 31, 2024
    affected <= 4.1.2

    Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to craft malicious Urls that certain functions in IdentityServer will incorrectly treat as local and trusted. If such a Url is returned as a redirect, some browsers