A vulnerability, which was classified as problematic, was found in zlt2000 microservices-platform up to 6.0.0. This affects the function onLogoutSuccess of the file src/main/java/com/central/oauth/handler/OauthLogoutSuccessHandler.java. The manipulation of the argument redirect_url leads to open redirect. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://vuldb.com/?id.319233 | technical description vdb entry |
https://vuldb.com/?ctiid.319233 | signature permissions required |
https://vuldb.com/?submit.623477 | third party advisory |
https://github.com/zlt2000/microservices-platform/issues/78 | issue tracking |
https://github.com/zlt2000/microservices-platform/issues/78#issue-3264847333 | exploit issue tracking |