Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/redirect.go, such as for the //foo//example.com substring.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/sourcegraph/sourcegraph(Go) | 0 | 3.14.4 | N/A |
| github.com/sourcegraph/sourcegraph(Go) | 3.15.0 | 3.15.1 | N/A |
CVSS Metrics