2020-10-10 19:01:40 +00:00
{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org" ,
2022-08-29 21:00:36 +00:00
"ID" : "CVE-2020-26938" ,
"STATE" : "PUBLIC"
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "n/a" ,
"version" : {
"version_data" : [
{
"version_value" : "n/a"
}
]
}
}
]
} ,
"vendor_name" : "n/a"
}
]
}
2020-10-10 19:01:40 +00:00
} ,
2022-08-29 21:00:36 +00:00
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
2020-10-10 19:01:40 +00:00
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2022-08-29 21:00:36 +00:00
"value" : "In oauth2-server (aka node-oauth2-server) through 3.1.1, the value of the redirect_uri parameter received during the authorization and token request is checked against an incorrect URI pattern (\"[a-zA-Z][a-zA-Z0-9+.-]+:\") before making a redirection. This allows a malicious client to pass an XSS payload through the redirect_uri parameter while making an authorization request. NOTE: this vulnerability is similar to CVE-2020-7741."
}
]
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "n/a"
}
]
}
]
} ,
"references" : {
"reference_data" : [
{
"refsource" : "MISC" ,
"name" : "https://github.com/oauthjs/node-oauth2-server/issues/637" ,
"url" : "https://github.com/oauthjs/node-oauth2-server/issues/637"
} ,
{
"url" : "https://github.com/oauthjs/node-oauth2-server/blob/91d2cbe70a0eddc53d72def96864e2de0fd41703/lib/validator/is.js#L12" ,
"refsource" : "MISC" ,
"name" : "https://github.com/oauthjs/node-oauth2-server/blob/91d2cbe70a0eddc53d72def96864e2de0fd41703/lib/validator/is.js#L12"
} ,
{
"url" : "https://github.com/oauthjs/node-oauth2-server/blob/91d2cbe70a0eddc53d72def96864e2de0fd41703/lib/grant-types/authorization-code-grant-type.js#L143" ,
"refsource" : "MISC" ,
"name" : "https://github.com/oauthjs/node-oauth2-server/blob/91d2cbe70a0eddc53d72def96864e2de0fd41703/lib/grant-types/authorization-code-grant-type.js#L143"
} ,
{
"url" : "https://tools.ietf.org/html/rfc3986#section-3" ,
"refsource" : "MISC" ,
"name" : "https://tools.ietf.org/html/rfc3986#section-3"
} ,
{
"url" : "https://tools.ietf.org/html/rfc6749#section-3.1.2" ,
"refsource" : "MISC" ,
"name" : "https://tools.ietf.org/html/rfc6749#section-3.1.2"
2020-10-10 19:01:40 +00:00
}
]
}
}