Логотип exploitDog
bind:CVE-2021-21377
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-21377

Количество 2

Количество 2

nvd логотип

CVE-2021-21377

почти 5 лет назад

OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-g4rf-pc26-6hmr

почти 5 лет назад

OMERO webclient does not validate URL redirects on login or switching group.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-21377

OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting.

CVSS3: 4.8
0%
Низкий
почти 5 лет назад
github логотип
GHSA-g4rf-pc26-6hmr

OMERO webclient does not validate URL redirects on login or switching group.

CVSS3: 4.8
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу