The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused by improper input validation and a violation of RFC-6819
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/bitly/oauth2_proxy(Go) | 0 | 2.2.0 | N/A |
CVSS Metrics