[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] CVE-2022-47500: Apache Helix: Open redirect
From:       Junkai Xue <jxue () apache ! org>
Date:       2022-12-16 22:38:23
Message-ID: 57f22782-ca9e-e289-0003-f2044fe5ff61 () apache ! org
[Download RAW message or body]

Severity: low

Description:

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation \
Apache Helix UI component.This issue affects Apache Helix all releases from 0.8.0 to 1.0.4.



Solution: removed the the forward component since it was improper designed for UI embedding.

  User please upgrade to 1.1.0 to fix this issue.

Credit:

This issue was discovered by Everardo Padilla Saca (reporter)

References:

https://helix.apache.org/
https://www.cve.org/CVERecord?id=CVE-2022-47500


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic