Skip to content

Fix improper redirect URL validation for /web/sso_confirm#55398

Merged
Joerger merged 2 commits intomasterfrom
joerger/fix-sso-arbitrary-host
Jun 5, 2025
Merged

Fix improper redirect URL validation for /web/sso_confirm#55398
Joerger merged 2 commits intomasterfrom
joerger/fix-sso-arbitrary-host

Conversation

@Joerger
Copy link
Copy Markdown
Contributor

@Joerger Joerger commented Jun 3, 2025

Ported from https://github.com/gravitational/teleport-private/pull/1975

Changelog: Fix improper redirect URL validation for SSO login which could be taken advantage of in a phishing attack.

Note: already backported to v17

…or proxy redirect.

* Ensure /web/sso_confirm is used as a relative redirect URL during callback.
@Joerger Joerger requested review from fheinecke and r0mant June 3, 2025 15:20
@github-actions github-actions Bot requested review from hugoShaka and kiosion June 3, 2025 15:21
@Joerger Joerger changed the title Fix improper redirect URL validation for/web/sso_confirm Fix improper redirect URL validation for /web/sso_confirm Jun 3, 2025
@r0mant
Copy link
Copy Markdown
Collaborator

r0mant commented Jun 3, 2025

@Joerger Please don't forget to backport this to v18 before the release.

@Joerger Joerger added this pull request to the merge queue Jun 5, 2025
Merged via the queue into master with commit 4e94068 Jun 5, 2025
40 checks passed
@Joerger Joerger deleted the joerger/fix-sso-arbitrary-host branch June 5, 2025 14:22
@backport-bot-workflows
Copy link
Copy Markdown
Contributor

@Joerger See the table below for backport results.

Branch Result
branch/v17 Failed
branch/v18 Create PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants