CVE-2022-36663

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
06/09/2022
Last modified:
09/09/2022

Description

Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gluu:oxauth:*:*:*:*:*:*:*:* 4.4.1 (excluding)