Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhxg-2xf7-4xwx

Опубликовано: 19 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Apache Helix UI vulnerable to Open Redirect

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache Helix all releases from 0.8.0 to and including 1.0.4. Solution: removed the the forward component since it was improper designed for UI embedding. User please upgrade to 1.1.0 to fix this issue.

Пакеты

Наименование

org.apache.helix:helix

maven
Затронутые версииВерсия исправления

>= 0.8.0, < 1.1.0

1.1.0

EPSS

Процентиль: 86%
0.0274
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 6.1
nvd
около 3 лет назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache Helix all releases from 0.8.0 to 1.0.4. Solution: removed the the forward component since it was improper designed for UI embedding.  User please upgrade to 1.1.0 to fix this issue.

EPSS

Процентиль: 86%
0.0274
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601