Описание
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache Helix all releases from 0.8.0 to 1.0.4.
Solution: removed the the forward component since it was improper designed for UI embedding.
User please upgrade to 1.1.0 to fix this issue.
Ссылки
- Issue TrackingVendor Advisory
- Issue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 0.8.0 (включая) до 1.0.4 (включая)
cpe:2.3:a:apache:helix:*:*:*:*:*:*:*:*
EPSS
Процентиль: 86%
0.0274
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-601
Связанные уязвимости
EPSS
Процентиль: 86%
0.0274
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-601