Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6gf2-ffq8-gcww

Опубликовано: 08 янв. 2025
Источник: github
Github: Прошло ревью
CVSS4: 1.9

Описание

GHSL-2024-288: SickChill open redirect in login

SickChill is an automatic video library manager for TV shows. A user-controlled login endpoint's next_ parameter takes arbitrary content. Prior to commit c7128a8946c3701df95c285810eb75b2de18bf82, an authenticated attacker may use this to redirect the user to arbitrary destinations, leading to open redirect. Commit c7128a8946c3701df95c285810eb75b2de18bf82 changes the login page to redirect to settings.DEFAULT_PAGE instead of to the next parameter.

Пакеты

Наименование

sickchill

pip
Затронутые версииВерсия исправления

<= 2024.3.1

Отсутствует

EPSS

Процентиль: 64%
0.00474
Низкий

1.9 Low

CVSS4

Дефекты

CWE-601

Связанные уязвимости

nvd
около 1 года назад

SickChill is an automatic video library manager for TV shows. A user-controlled `login` endpoint's `next_` parameter takes arbitrary content. Prior to commit c7128a8946c3701df95c285810eb75b2de18bf82, an authenticated attacker may use this to redirect the user to arbitrary destinations, leading to open redirect. Commit c7128a8946c3701df95c285810eb75b2de18bf82 changes the login page to redirect to `settings.DEFAULT_PAGE` instead of to the `next` parameter.

EPSS

Процентиль: 64%
0.00474
Низкий

1.9 Low

CVSS4

Дефекты

CWE-601