An issue was found in the redirect_uri validation logic that allows for a bypass of otherwise explicitly allowed hosts.
{
"severity": "HIGH",
"cwe_ids": [
"CWE-346",
"CWE-601"
],
"nvd_published_at": "2024-04-17T14:15:08Z",
"github_reviewed": true,
"github_reviewed_at": "2024-04-17T17:31:12Z"
}