CVE-2017-1000484 Information

Description

By linking to a specific url in Plone 2.5-5.1rc1 with a parameter an attacker could send you to his own website. On its own this is not so bad: the attacker could more easily link directly to his own website instead. But in combination with another attack you could be sent to the Plone login form and login then get redirected to the specific url and then get a second redirect to the attacker website. (The specific url can be seen by inspecting the hotfix code but we don’t want to make it too easy for attackers by spelling it out here.)

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

https://plone.org/security/hotfix/20171128/an-open-redirection-when-calling-a-specific-url https://plone.org/security/hotfix/20171128/an-open-redirection-when-calling-a-specific-url By linking to a specific url in Plone 2.5-5.1rc1 with a parameter an attacker could send you to his own website. On its own this is not so bad: the attacker could more easily link directly to his own website instead. But in combination with another attack you could be sent to the Plone login form and login then get redirected to the specific url and then get a second redirect to the attacker website. (The specific url can be seen by inspecting the hotfix code but we don’t want to make it too easy for attackers by spelling it out here.)

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

Share on: