openam-jp / openam

Other
32 stars 15 forks source link

Open Redirect Vulnerability #259

Closed tsujiguchitky closed 2 years ago

tsujiguchitky commented 2 years ago

Description

OpenAM (OpenAM Consortium Edition) has an open redirect vulnerability in logout URL.

After performing some steps, accessing the logout URL with a malformed parameter can redirect the user to an arbitrary URL.