Open Redirect
Moderate severity
GitHub Reviewed
Published
May 27, 2021
in
tenancy/multi-tenant
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
May 27, 2021
Reviewed
May 27, 2021
Published to the GitHub Advisory Database
Mar 18, 2022
Last updated
Feb 1, 2023
Impact
In some situations, it is possible to have open redirects where users can be redirected from your site to any other site using a specially crafted URL.
This is only the case for installations where the default Hostname Identification is used and the environment uses tenants that have
force_https
set totrue
(default:false
)Patches
Version 5.7.2 contains the relevant patches to fix this bug. Stripping the URL from special characters to prevent specially crafted URL's from being redirected to.
Workarounds
There is a simple way to work around the security issue
force_https
to every tenant tofalse
References
https://nvd.nist.gov/vuln/detail/CVE-2018-11784
For more information
If you have any questions or comments about this advisory:
References