Total vulnerabilities in the database
A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this parameter, which would redirect the user after auth and send the authorization token to the redirected domain.
Software | From | Fixed in |
---|---|---|
zscaler / client_connector | - | 3.7 |
zscaler / client_connector | - | 1.4 |
zscaler / client_connector | - | 1.10.2 |
zscaler / client_connector | - | 1.10.1 |
zscaler / client_connector | - | 1.9.3 |
zscaler / client_connector | - | 3.9 |