CVE-2019-9837: URL Redirection to Untrusted Site (Open Redirect)
(updated )
Doorkeeper::OpenidConnect
(aka the OpenID Connect extension for Doorkeeper) has an open redirect via the redirect_uri
field in an OAuth authorization request (that results in an error response) with the openid
scope and a prompt=none value
. This allows phishing attacks against the authorization flow.
References
Detect and mitigate CVE-2019-9837 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →