Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-21337

Опубликовано: 08 мар. 2021
Источник: nvd
CVSS3: 5.7
CVSS3: 6.1
CVSS2: 5.8
EPSS Низкий

Описание

Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 there is an open redirect vulnerability. A maliciously crafted link to the login form and login functionality could redirect the browser to a different website. The problem has been fixed in version 2.6.1. Depending on how you have installed Products.PluggableAuthService, you should change the buildout version pin to 2.6.1 and re-run the buildout, or if you used pip simply do `pip install "Products.PluggableAuthService>=2.6.1".

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zope:products.pluggableauthservice:*:*:*:*:*:*:*:*
Версия до 2.6.1 (исключая)

EPSS

Процентиль: 82%
0.01798
Низкий

5.7 Medium

CVSS3

6.1 Medium

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 5.7
github
почти 5 лет назад

URL Redirection to Untrusted Site ('Open Redirect') in Products.PluggableAuthService

EPSS

Процентиль: 82%
0.01798
Низкий

5.7 Medium

CVSS3

6.1 Medium

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-601