{"id":"CVE-2017-1000070","aliases":["GHSA-jm34-xm8m-w958"],"url":"https://o3.security/vulnerability/CVE-2017-1000070","summary":"Open Redirect in oauth2_proxy","details":"The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused by improper input validation and a violation of RFC-6819","published":"2017-07-17T13:18:18.220Z","modified":"2026-07-08T10:54:13.888578Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/bitly/oauth2_proxy","fixedVersion":"2.2.0"}],"fix":{"url":"https://github.com/bitly/oauth2_proxy/pull/359","label":"bitly/oauth2_proxy#359"},"references":[{"type":"FIX","url":"https://github.com/bitly/oauth2_proxy/pull/359"},{"type":"ARTICLE","url":"https://tools.ietf.org/html/rfc6819#section-5.2.3.5"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T10:54:13.888578Z"}}