Skip to content

Conversation

@Potherca
Copy link
Member

@Potherca Potherca commented Jun 9, 2025

This MR is a fix for a potential attack vector (CWE-601 - URL Redirection to Untrusted Site a.k.a. 'Open Redirect') in the SeverController.

This MR is placed in "Draft", as I have not yet validated the code on a running instance.

@Potherca Potherca force-pushed the fix/CLN-006-open-redirect branch from 32d67ff to 54c843f Compare June 9, 2025 12:46
Potherca added 2 commits June 9, 2025 17:31
Resolves CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
@Potherca Potherca force-pushed the fix/CLN-006-open-redirect branch from 1417fff to 4bc8355 Compare June 9, 2025 16:32
@Potherca Potherca self-assigned this Jun 9, 2025
@Potherca Potherca requested a review from ylebre June 9, 2025 17:33
@Potherca Potherca linked an issue Jun 20, 2025 that may be closed by this pull request
@Potherca Potherca marked this pull request as ready for review June 26, 2025 15:41
@Potherca Potherca merged commit 603316c into main Jun 27, 2025
23 checks passed
@Potherca Potherca deleted the fix/CLN-006-open-redirect branch June 27, 2025 09:08
@Potherca Potherca added this to the v0.11.0 milestone Oct 13, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

redirect_uri in authorize request is not validated

3 participants