Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-28724

Опубликовано: 06 дек. 2015
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.

An open redirect flaw was found in the WSGI library python-werkzeug. When URL_PATH starts with a double slash, followed by an arbitrary URL without a scheme, python-werkzeug could redirect applications to that arbitrary URL. This flaw allows an attacker to use this technique to redirect victims to phishing websites controlled by an attacker or to use this flaw to chain vulnerabilities.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2python-werkzeugOut of support scope
Red Hat Enterprise Linux 8python-werkzeugNot affected
Red Hat OpenShift Container Platform 4python-werkzeugNot affected
Red Hat OpenStack Platform 16.1python-werkzeugNot affected
Red Hat Quay 3python-werkzeugNot affected
Red Hat Satellite 6python-werkzeugWill not fix
Red Hat Software Collectionspython27-python-werkzeugNot affected
Red Hat Update Infrastructure 3 for Cloud Providerspython-werkzeugOut of support scope
Red Hat Virtualization 4python-werkzeugNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=1899267python-werkzeug: open redirect via double slash in the URL

EPSS

Процентиль: 76%
0.00923
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 5 лет назад

Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.

CVSS3: 6.1
nvd
около 5 лет назад

Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.

CVSS3: 6.1
debian
около 5 лет назад

Open redirect vulnerability in werkzeug before 0.11.6 via a double sla ...

CVSS3: 6.1
github
почти 5 лет назад

Open Redirect in werkzeug

EPSS

Процентиль: 76%
0.00923
Низкий

5.4 Medium

CVSS3