Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-69725

Опубликовано: 19 фев. 2026
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect victim users to malicious websites using the legitimate website domain.

A flaw was found in go-chi/chi, a Go (programming language) HTTP router. This open redirect vulnerability, specifically within the RedirectSlashes function, allows a remote attacker to redirect users to malicious websites. This occurs by manipulating the legitimate website's domain, potentially leading to phishing attacks or other forms of social engineering.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/bitwarden-sdk-server-rhel9Fix deferred
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-operator-bundleFix deferred
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-operator-rhel9Fix deferred
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Fix deferred
Gatekeeper 3gatekeeper/gatekeeper-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/loki-operator-bundleFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/loki-rhel9-operatorFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/lokistack-gateway-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/opa-openshift-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2441027go-chi/chi: Go-chi/chi: Open Redirect vulnerability allows redirection to malicious websites

EPSS

Процентиль: 13%
0.00042
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
около 1 месяца назад

An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect victim users to malicious websites using the legitimate website domain.

CVSS3: 4.7
nvd
около 1 месяца назад

An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect victim users to malicious websites using the legitimate website domain.

CVSS3: 4.7
debian
около 1 месяца назад

An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlash ...

CVSS3: 4.7
github
около 1 месяца назад

An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect victim users to malicious websites using the legitimate website domain.

EPSS

Процентиль: 13%
0.00042
Низкий

4.7 Medium

CVSS3