Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8hp3-rmr7-xh88

Опубликовано: 17 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Open Redirect in github.com/greenpau/caddy-security

All versions of the package github.com/greenpau/caddy-security are vulnerable to Open Redirect via the redirect_url parameter. An attacker could perform a phishing attack and trick users into visiting a malicious website by crafting a convincing URL with this parameter. To exploit this vulnerability, the user must take an action, such as clicking on a portal button or using the browser’s back button, to trigger the redirection.

Пакеты

Наименование

github.com/greenpau/caddy-security

go
Затронутые версииВерсия исправления

<= 1.1.23

Отсутствует

EPSS

Процентиль: 27%
0.00097
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 5.4
nvd
почти 2 года назад

All versions of the package github.com/greenpau/caddy-security are vulnerable to Open Redirect via the redirect_url parameter. An attacker could perform a phishing attack and trick users into visiting a malicious website by crafting a convincing URL with this parameter. To exploit this vulnerability, the user must take an action, such as clicking on a portal button or using the browser’s back button, to trigger the redirection.

EPSS

Процентиль: 27%
0.00097
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-601