VDB
CVE-2026-83589
CVE-2026-83589
PUBLISHED
CVSS 6.1 MEDIUM
Reported by redhat · Published October 1, 2026
A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft.
Risk Scores
CVSS 3.1
6.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1790704224 |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1790706478 |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1790724885 |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1790724885 |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1790704224 |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1790706478 |
| Red Hat | Red Hat OpenShift Container Platform 4 |
Timeline
- Oct 1, 2026 Coalition ESS Score
- Oct 1, 2026 CVE Published
- Oct 2, 2026 EPSS Score
- Oct 7, 2026 EPSS Score
- Oct 7, 2026 CVE Updated
- Oct 7, 2026 Distribution Patch
- Oct 7, 2026 Distribution Patch
- Oct 7, 2026 Distribution Patch
- Oct 7, 2026 Security Advisory
- Oct 7, 2026 Security Advisory
- Oct 7, 2026 Security Advisory
References
- RHSA-2026:74380 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:74383 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:74429 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2518379 issue-trackingx_refsource_REDHAT