Vulnerability Description
Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/redirect.go, such as for the //foo//example.com substring.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sourcegraph | Sourcegraph | < 3.15.1 |
Related Weaknesses (CWE)
References
- https://github.com/sourcegraph/sourcegraph/blob/master/CHANGELOG.mdRelease NotesThird Party Advisory
- https://github.com/sourcegraph/sourcegraph/commit/c0f48172e815c7f66471a38f0a06d1PatchThird Party Advisory
- https://github.com/sourcegraph/sourcegraph/compare/v3.15.0...v3.15.1Release NotesThird Party Advisory
- https://github.com/sourcegraph/sourcegraph/pull/10167PatchThird Party Advisory
- https://securitylab.github.com/advisories/GHSL-2020-085-sourcegraphExploitThird Party Advisory
- https://github.com/sourcegraph/sourcegraph/blob/master/CHANGELOG.mdRelease NotesThird Party Advisory
- https://github.com/sourcegraph/sourcegraph/commit/c0f48172e815c7f66471a38f0a06d1PatchThird Party Advisory
- https://github.com/sourcegraph/sourcegraph/compare/v3.15.0...v3.15.1Release NotesThird Party Advisory
- https://github.com/sourcegraph/sourcegraph/pull/10167PatchThird Party Advisory
- https://securitylab.github.com/advisories/GHSL-2020-085-sourcegraphExploitThird Party Advisory
FAQ
What is CVE-2020-12283?
CVE-2020-12283 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/redirect.go, such as for the //foo//example.com sub...
How severe is CVE-2020-12283?
CVE-2020-12283 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12283?
Check the references section above for vendor advisories and patch information. Affected products include: Sourcegraph Sourcegraph.