Glewlwyd SSO server 2.x through 2.7.6 allows open redirection via redirect_uri.
{ "binaries": [ { "binary_version": "2.6.1-1build1", "binary_name": "glewlwyd" }, { "binary_version": "2.6.1-1build1", "binary_name": "glewlwyd-common" } ] }
{ "binaries": [ { "binary_version": "2.7.6+ds-2build2", "binary_name": "glewlwyd" }, { "binary_version": "2.7.6+ds-2build2", "binary_name": "glewlwyd-common" } ] }
{ "binaries": [ { "binary_version": "2.7.6+ds-2build3", "binary_name": "glewlwyd" }, { "binary_version": "2.7.6+ds-2build3", "binary_name": "glewlwyd-common" } ] }