Логотип exploitDog
bind:CVE-2025-64481
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-64481

Количество 2

Количество 2

nvd логотип

CVE-2025-64481

3 месяца назад

Datasette is an open source multi-tool for exploring and publishing data. In versions 0.65.1 and below and 1.0a0 through 1.0a19, deployed instances of Datasette include an open redirect vulnerability. Hits to the path //example.com/foo/bar/ (the trailing slash is required) will redirect the user to https://example.com/foo/bar. This problem has been patched in both Datasette 0.65.2 and 1.0a21. To workaround this issue, if Datasette is running behind a proxy, that proxy could be configured to replace // with / in incoming request URLs.

EPSS: Низкий
github логотип

GHSA-w832-gg5g-x44m

3 месяца назад

Open redirect endpoint in Datasette

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-64481

Datasette is an open source multi-tool for exploring and publishing data. In versions 0.65.1 and below and 1.0a0 through 1.0a19, deployed instances of Datasette include an open redirect vulnerability. Hits to the path //example.com/foo/bar/ (the trailing slash is required) will redirect the user to https://example.com/foo/bar. This problem has been patched in both Datasette 0.65.2 and 1.0a21. To workaround this issue, if Datasette is running behind a proxy, that proxy could be configured to replace // with / in incoming request URLs.

0%
Низкий
3 месяца назад
github логотип
GHSA-w832-gg5g-x44m

Open redirect endpoint in Datasette

0%
Низкий
3 месяца назад

Уязвимостей на страницу