Lucene search

K
osvGoogleOSV:CVE-2021-32645
HistoryMay 27, 2021 - 5:15 p.m.

CVE-2021-32645

2021-05-2717:15:08
Google
osv.dev
19
tenancy multi-tenant
open redirect
laravel web framework
security vulnerability
force_https
connection security

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

43.6%

Tenancy multi-tenant is an open source multi-domain controller for the Laravel web framework. In some situations, it is possible to have open redirects where users can be redirected from your site to any other site using a specially crafted URL. This is only the case for installations where the default Hostname Identification is used and the environment uses tenants that have force_https set to true (default: false). Version 5.7.2 contains the relevant patches to fix this bug. Stripping the URL from special characters to prevent specially crafted URL’s from being redirected to. As a work around users can set the force_https to every tenant to false, however this may degrade connection security.

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

43.6%

Related for OSV:CVE-2021-32645