Логотип exploitDog
bind:CVE-2020-15242
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-15242

Количество 2

Количество 2

nvd логотип

CVE-2020-15242

больше 4 лет назад

Next.js versions >=9.5.0 and <9.5.4 are vulnerable to an Open Redirect. Specially encoded paths could be used with the trailing slash redirect to allow an open redirect to occur to an external site. In general, this redirect does not directly harm users although can allow for phishing attacks by redirecting to an attackers domain from a trusted domain. The issue is fixed in version 9.5.4.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-x56p-c8cg-q435

больше 4 лет назад

Open Redirect in Next.js versions

CVSS3: 4.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-15242

Next.js versions >=9.5.0 and <9.5.4 are vulnerable to an Open Redirect. Specially encoded paths could be used with the trailing slash redirect to allow an open redirect to occur to an external site. In general, this redirect does not directly harm users although can allow for phishing attacks by redirecting to an attackers domain from a trusted domain. The issue is fixed in version 9.5.4.

CVSS3: 4.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-x56p-c8cg-q435

Open Redirect in Next.js versions

CVSS3: 4.7
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу