Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-82j9-wfcf-9v2h

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.1

Описание

Plone Open Redirect Vulnerability

An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redirect to an attacker's site.

Пакеты

Наименование

Plone

pip
Затронутые версииВерсия исправления

>= 4.0, < 4.3.20

4.3.20

Наименование

Plone

pip
Затронутые версииВерсия исправления

>= 5.0rc1, < 5.1.7

5.1.7

Наименование

Plone

pip
Затронутые версииВерсия исправления

>= 5.2.0, < 5.2.2

5.2.2

EPSS

Процентиль: 56%
0.0034
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 6.1
redhat
около 6 лет назад

An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redirect to an attacker's site.

CVSS3: 6.1
nvd
около 6 лет назад

An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redirect to an attacker's site.

EPSS

Процентиль: 56%
0.0034
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-601