Loading HuntDB...

CVE-2017-16652

UNKNOWN
Published 2018-06-13T16:00:00
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2017-16652. We'll provide specific mitigation strategies based on your environment and risk profile.

No CVSS data available

Description

An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the _target_path parameter and generates a redirect response, but no check is performed on the path, which could be an absolute URL to an external domain. This Open redirect vulnerability can be exploited for example to mount effective phishing attacks.

Available Exploits

No exploits available for this CVE.

Related News

No news articles found for this CVE.

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

✓ GitHub Reviewed MODERATE

Symfony Open Redirect

GHSA-r7p7-qr7p-2rrf

Advisory Details

An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. `DefaultAuthenticationSuccessHandler` or `DefaultAuthenticationFailureHandler` takes the content of the `_target_path` parameter and generates a redirect response, but no check is performed on the path, which could be an absolute URL to an external domain. This Open redirect vulnerability can be exploited for example to mount effective phishing attacks.

Affected Packages

Packagist symfony/symfony
ECOSYSTEM: ≥2.7.0 <2.7.38
Packagist symfony/symfony
ECOSYSTEM: ≥2.8.0 <2.8.31
Packagist symfony/symfony
ECOSYSTEM: ≥3.2.0 <3.2.14
Packagist symfony/symfony
ECOSYSTEM: ≥3.3.0 <3.3.13
Packagist symfony/security-http
ECOSYSTEM: ≥2.7.0 <2.7.38
Packagist symfony/security-http
ECOSYSTEM: ≥2.8.0 <2.8.31
Packagist symfony/security-http
ECOSYSTEM: ≥3.2.0 <3.2.14
Packagist symfony/security-http
ECOSYSTEM: ≥3.3.0 <3.3.13
Packagist symfony/security
ECOSYSTEM: ≥2.7.0 <2.7.38
Packagist symfony/security
ECOSYSTEM: ≥2.8.0 <2.8.31
Packagist symfony/security
ECOSYSTEM: ≥3.2.0 <3.2.14
Packagist symfony/security
ECOSYSTEM: ≥3.3.0 <3.3.13

CVSS Scoring

CVSS Score

5.0

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Advisory provided by GitHub Security Advisory Database. Published: May 14, 2022, Modified: October 31, 2023

References

Published: 2018-06-13T16:00:00
Last Modified: 2024-08-05T20:27:04.285Z
Copied to clipboard!