PT-2026-47239 · Unknown · Hsweb-Framework
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
hs-web hsweb-framework versions prior to 5.0.2
Description
An open redirect issue exists in the OAuth2 Client component. A remote attacker can manipulate the
OAuth2Client() function within the file hsweb-authorization/hsweb-authorization-oauth2/src/main/java/org/hswebframework/web/oauth2/server/OAuth2Client.java to redirect users to an arbitrary external site.Recommendations
Apply patch c2882679a9125cea52678151af5ae213cbd52579 to resolve the issue.
As a temporary workaround, restrict access to the
OAuth2Client() function until the patch is applied.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hsweb-Framework