Логотип exploitDog
bind:CVE-2021-32645
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-32645

Количество 2

Количество 2

nvd логотип

CVE-2021-32645

больше 4 лет назад

Tenancy multi-tenant is an open source multi-domain controller for the Laravel web framework. In some situations, it is possible to have open redirects where users can be redirected from your site to any other site using a specially crafted URL. This is only the case for installations where the default Hostname Identification is used and the environment uses tenants that have `force_https` set to `true` (default: `false`). Version 5.7.2 contains the relevant patches to fix this bug. Stripping the URL from special characters to prevent specially crafted URL's from being redirected to. As a work around users can set the `force_https` to every tenant to `false`, however this may degrade connection security.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4r8q-gv9j-3xx6

почти 4 года назад

Open Redirect

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-32645

Tenancy multi-tenant is an open source multi-domain controller for the Laravel web framework. In some situations, it is possible to have open redirects where users can be redirected from your site to any other site using a specially crafted URL. This is only the case for installations where the default Hostname Identification is used and the environment uses tenants that have `force_https` set to `true` (default: `false`). Version 5.7.2 contains the relevant patches to fix this bug. Stripping the URL from special characters to prevent specially crafted URL's from being redirected to. As a work around users can set the `force_https` to every tenant to `false`, however this may degrade connection security.

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4r8q-gv9j-3xx6

Open Redirect

CVSS3: 4.3
0%
Низкий
почти 4 года назад

Уязвимостей на страницу