The affected component is pyodata handling of OData __next URLs. The advisory attributes the flaw to insufficient validation of externally supplied __next URLs, allowing a malicious or compromised OData service to cause subsequent requests to be redirected to unintended destinations.
At a high level, the sequence is:
- An application uses
pyodata to query an OData service.
- The OData service supplies an externally controlled
__next value.
pyodata processes the value without adequately validating the destination, causing a request redirect.
- Sensitive authentication information may be disclosed and untrusted data may be injected into the application.
The record describes network reachability, low privileges required, high attack complexity, and no user interaction. The exact request sequence, authentication material affected, and specific caller contexts have not been documented.