MEDIUM 4.7 Maven
URL Redirection to Untrusted Site ('Open Redirect')
GHSA-jp55-vvmf-63mv · CVE-2022-23618
Published · Modified
Description
Impact
There's no protection against URL redirection to untrusted site, in particular some well known parameters (xredirect) can be used to perform such redirections.
Patches
The problem has been patched in XWiki 12.10.7 and XWiki 13.3RC1.
Workarounds
There's no known workaround for this issue.
References
https://jira.xwiki.org/browse/XWIKI-10309
For more information
If you have any questions or comments about this advisory:
- Open an issue in JIRA
- Email us at Security ML
References
- WEB https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-jp55-vvmf-63mv
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2022-23618
- WEB https://github.com/xwiki/xwiki-platform/commit/5251c02080466bf9fb55288f04a37671108f8096
- PACKAGE https://github.com/xwiki/xwiki-platform
- WEB https://jira.xwiki.org/browse/XWIKI-10309
Ready to move
Start Securing
Free, no credit card | First findings in minutes