GHSA-8xp4-5fqf-wj9gHighCVSS 8.0

Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote,...

Published
October 6, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (1)

📋 Description

Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision.

🔗 References (3)