VYPR

OAuth-server

by Red Hat

CVEs (2)

  • CVE-2024-11217MedNov 15, 2024
    risk 0.32cvss 4.9epss 0.00

    A vulnerability was found in the OAuth-server. OAuth-server logs the OAuth2 client secret when the logLevel is Debug higher for OIDC/GitHub/GitLab/Google IDPs login options.

  • CVE-2026-19078MedAug 11, 2026
    risk 0.28cvss 4.3epss

    A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an authenticated user,…