Fosite
Ory · 4 CVEs
CVE-2020-15233
MEDIUM
OAuth2 Redirect URL validity does not respect query parameters and character casing for loopback addresses
Oct 2, 2020
CVE-2020-15234
MEDIUM
Redirect URL matching ignores character casing
Oct 2, 2020
CVE-2020-15222
HIGH
Replay of private_key_jwt possible in ORY Fosite
Sep 24, 2020
CVE-2020-15223
HIGH
Ignored storage errors on token revokation in ORY Fosite
Sep 24, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2020-15233 | OAuth2 Redirect URL validity does not respect query parameters and character casing for loopback addresses | MEDIUM | 0.80% | Oct 2, 2020 |
| CVE-2020-15234 | Redirect URL matching ignores character casing | MEDIUM | 0.84% | Oct 2, 2020 |
| CVE-2020-15222 | Replay of private_key_jwt possible in ORY Fosite | HIGH | 0.87% | Sep 24, 2020 |
| CVE-2020-15223 | Ignored storage errors on token revokation in ORY Fosite | HIGH | 1.59% | Sep 24, 2020 |
Showing 1 to 4 of 4 CVEs