Lucene search

K
osvGoogleOSV:GHSA-733F-44F3-3FRW
HistoryMay 18, 2021 - 9:08 p.m.

gopkg.in/macaron.v1 Open redirect vulnerability

2021-05-1821:08:35
Google
osv.dev
13
macaron
open redirect
static handler
improper request santization
software

EPSS

0.001

Percentile

43.2%

macaron before 1.3.7 has an open redirect in the static handler. Due to improper request santization, a specifically crafted URL can cause the static file handler to redirect to an attacker chosen URL, allowing for open redirect attacks.