{"id":"CVE-2020-5233","aliases":["BIT-oauth2-proxy-2020-5233","GHSA-qqxw-m5fj-f7gv"],"url":"https://o3.security/vulnerability/CVE-2020-5233","summary":"The pattern '/\\domain.com' is not disallowed when redirecting, allowing for open redirect","details":"OAuth2 Proxy before 5.0 has an open redirect vulnerability. Authentication tokens could be silently harvested by an attacker. This has been patched in version 5.0.","published":"2020-01-30T19:15:11.883Z","modified":"2026-07-09T00:38:13.472457Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.01124,"percentile":0.63303,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Go","name":"github.com/oauth2-proxy/oauth2-proxy","fixedVersion":"5.0.0"}],"fix":{"url":"https://github.com/pusher/oauth2_proxy/commit/a316f8a06f3c0ca2b5fc5fa18a91781b313607b2","label":"pusher/oauth2_proxy@a316f8a"},"references":[{"type":"ADVISORY","url":"https://github.com/pusher/oauth2_proxy/releases/tag/v5.0.0"},{"type":"FIX","url":"https://github.com/pusher/oauth2_proxy/commit/a316f8a06f3c0ca2b5fc5fa18a91781b313607b2"},{"type":"FIX","url":"https://github.com/pusher/oauth2_proxy/security/advisories/GHSA-qqxw-m5fj-f7gv"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T00:38:13.472457Z"}}