Skip to content

Open Redirects #2952

@dpfaffenbauer

Description

@dpfaffenbauer

Problem Statement
Several controllers do not validate redirect targets.

Description

  • The _redirect parameter can be set arbitrarily.
  • So far, no redirects have been identified that exfiltrate sensitive data.

Impact

  • Currently no proven exploitation.
  • Potential security risk in case of future changes or extensions.

Mitigation

  • Enforce an allowlist for redirect targets.
  • Require relative URLs only.

@raphael-kat @papillo-solutions

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions