Skip to content

[v17] Fix improper redirect URL validation for /web/sso_confirm#55399

Merged
Joerger merged 1 commit intobranch/v17from
joerger/v17/fix-sso-arbitrary-host
Jun 3, 2025
Merged

[v17] Fix improper redirect URL validation for /web/sso_confirm#55399
Joerger merged 1 commit intobranch/v17from
joerger/v17/fix-sso-arbitrary-host

Conversation

@Joerger
Copy link
Copy Markdown
Contributor

@Joerger Joerger commented Jun 3, 2025

Backport #55398 to branch/v17

Changelog: Fix improper redirect URL validation for SSO login which could be taken advantage of in a phishing attack.

…or proxy redirect.

* Ensure /web/sso_confirm is used as a relative redirect URL during callback.
@Joerger Joerger added this pull request to the merge queue Jun 3, 2025
Merged via the queue into branch/v17 with commit b211f1d Jun 3, 2025
42 checks passed
@Joerger Joerger deleted the joerger/v17/fix-sso-arbitrary-host branch June 3, 2025 22:21
@doggydogworld doggydogworld mentioned this pull request Jun 3, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants