GHSA-8xp4-5fqf-wj9gHighCVSS 8.0
Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote,...
🔗 CVE IDs covered (1)
📋 Description
Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision.