Open
Description
The function respondToExitIframeRequest
will redirect to any URL passed in the exitIframe
parameter.
We could simply check that the exitIframe
parameter starts with /auth?
to limit the possibilities of open redirects.
Note: I didn't report this as a security vulnerability as open redirects are ineligible.
Metadata
Metadata
Assignees
Labels
No labels