PT-2026-103760 · Red Hat · Red Hat Openshift Container Platform 4
CVE-2026-83589
·
Published
2026-10-01
·
Updated
2026-10-01
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (
rd) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft.Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Openshift Container Platform 4