The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused by improper input validation and a violation of RFC-6819
| Software | From | Fixed in |
|---|---|---|
| oauth2_proxy_project / oauth2_proxy | - | 2.1.x |
github.com/bitly/oauth2_proxy
|
- | 2.2 |