Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-12666

Опубликовано: 06 мая 2020
Источник: redhat
CVSS3: 6.1

Описание

macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.com/ URL.

A flaw was found in macaron. Path URLs aren't cleaned before being redirected creating an open redirect in the static handler.

Отчет

This issue has a low impact on both OpenShift Container Platform and OpenShift Service Mesh grafana containers. As neither components make use of the Static handler the impact is Low. A future version of Grafana may use the Macaron Static handler so we may fix this in a future release. Red Hat Ceph Storage (RHCS) versions 3 and 4 use Grafana where the affected version of the macaron package is delivered. However the Static handler is not used by Ceph hence the impact by this vulnerability is Low. Ceph-2 has reached End of Extended Life Cycle Support and no longer fixing moderates/lows.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2grafanaOut of support scope
Red Hat Ceph Storage 3grafanaAffected
Red Hat Ceph Storage 3grafana-containerAffected
Red Hat Ceph Storage 4rhceph/rhceph-4-dashboard-rhel8Affected
Red Hat OpenShift Container Platform 3.11openshift3/grafanaFix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-grafanaFix deferred
Red Hat Storage 3grafanaAffected
Openshift Service Mesh 1.1kialiFixedRHSA-2020:336906.08.2020
OpenShift Service Mesh 1.1iorFixedRHSA-2020:336906.08.2020
OpenShift Service Mesh 1.1servicemeshFixedRHSA-2020:336906.08.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=1850034macaron: open redirect in the static handler

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
почти 6 лет назад

macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.com/ URL.

CVSS3: 6.1
github
больше 4 лет назад

gopkg.in/macaron.v1 Open Redirect vulnerability

6.1 Medium

CVSS3