Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53683

Опубликовано: 30 авг. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow.

Отчет

Rated Moderate because exploitation requires a victim to follow a crafted link, and the direct technical impact is limited to a client-side redirect with no data disclosure or modification. The practical risk is phishing/social-engineering enablement rather than a direct technical compromise.

Меры по смягчению последствий

Eliminate arbitrary URL redirects. If a post-reset return URL is required, allowlist same-origin paths only, or validate against a strict allowlist of trusted hosts and the HTTPS scheme. Prefer server-generated, signed return tokens instead of raw URLs, and ensure the UI uses safe navigation helpers that reject dangerous schemes and external origins.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10ipaFix deferred
Red Hat Enterprise Linux 6ipaOut of support scope
Red Hat Enterprise Linux 7ipaFix deferred
Red Hat Enterprise Linux 8ipaFix deferred
Red Hat Enterprise Linux 9ipaFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2487512FreeIPA: idm: IdM/FreeIPA Web UI - Client-side open redirect in reset_password.html

EPSS

Процентиль: 7%
0.00171
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
3 дня назад

reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow.

CVSS3: 4.3
nvd
4 дня назад

reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow.

CVSS3: 4.3
debian
4 дня назад

reset_password.html parses query string parameters and uses the 'url' ...

CVSS3: 4.3
github
4 дня назад

reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow.

EPSS

Процентиль: 7%
0.00171
Низкий

4.3 Medium

CVSS3

Уязвимость CVE-2026-53683