Skip to content
This repository has been archived by the owner on Jul 30, 2021. It is now read-only.

Open Redirect

Moderate
puncsky published GHSA-6wcq-7r33-gw8x Nov 10, 2020

Package

No package listed

Affected versions

1.1.0

Patched versions

None

Description

Impact

Impacts can be many, and vary from theft of information and credentials, to the redirection to malicious websites containing attacker-controlled content, which in some cases even cause XSS attacks. So even though an open redirection might sound harmless at first, the impacts of it can be severe should it be exploitable.

Patches

The vulnerability will be patched in version 2.0.

Workarounds

Update to Version 2.0

References

https://cwe.mitre.org/data/definitions/601.html

Severity

Moderate

CVE ID

CVE-2020-26219

Weaknesses

No CWEs