Glewlwyd SSO server 2.x through 2.7.6 allows open redirection via redirect_uri.
{ "binaries": [ { "binary_name": "glewlwyd", "binary_version": "2.6.1-1build1" }, { "binary_name": "glewlwyd-common", "binary_version": "2.6.1-1build1" } ] }
{ "binaries": [ { "binary_name": "glewlwyd", "binary_version": "2.7.6+ds-2build2" }, { "binary_name": "glewlwyd-common", "binary_version": "2.7.6+ds-2build2" } ] }
{ "binaries": [ { "binary_name": "glewlwyd", "binary_version": "2.7.6+ds-3" }, { "binary_name": "glewlwyd-common", "binary_version": "2.7.6+ds-3" } ] }
{ "binaries": [ { "binary_name": "glewlwyd", "binary_version": "2.7.6+ds-2build3" }, { "binary_name": "glewlwyd-common", "binary_version": "2.7.6+ds-2build3" } ] }