Open Redirect Vulnerability in Okta OIDC Middleware
CVE-2022-3145

4.7MEDIUM

Key Information:

Vendor

Okta

Vendor
CVE Published:
12 January 2023

What is CVE-2022-3145?

An open redirect vulnerability is present in the Okta OIDC Middleware before version 5.0.0. This flaw can be exploited by attackers to redirect users to arbitrary URLs, potentially leading to phishing attempts or other malicious activities. The vulnerability allows unauthorized redirection, posing significant risks for users who may be misled by such redirects.

Affected Version(s)

Okta OIDC Middleware prior to 5.0.0

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.