Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5fwq-9x7j-2qpg

Опубликовано: 05 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 6.1

Описание

lorawan-stack Open Redirect vulnerability

lorawan-stack is an open source LoRaWAN network server. Prior to version 3.24.1, an open redirect exists on the login page of the lorawan stack server, allowing an attacker to supply a user controlled redirect upon sign in. This issue may allows malicious actors to phish users, as users assume they were redirected to the homepage on login. Version 3.24.1 contains a fix.

Пакеты

Наименование

go.thethings.network/lorawan-stack/v3

go
Затронутые версииВерсия исправления

< 3.24.1

3.24.1

EPSS

Процентиль: 44%
0.00212
Низкий

5.1 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 6.1
nvd
почти 3 года назад

lorawan-stack is an open source LoRaWAN network server. Prior to version 3.24.1, an open redirect exists on the login page of the lorawan stack server, allowing an attacker to supply a user controlled redirect upon sign in. This issue may allows malicious actors to phish users, as users assume they were redirected to the homepage on login. Version 3.24.1 contains a fix.

EPSS

Процентиль: 44%
0.00212
Низкий

5.1 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-601