Lucene search

K
osvGoogleOSV:GHSA-89R2-5G34-2G47
HistoryMay 14, 2022 - 1:04 a.m.

Symfony Open Redirect

2022-05-1401:04:20
Google
osv.dev
4

6.5 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.5%

An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the _failure_path input field of login forms, an attacker can work around the redirection target restrictions and effectively redirect the user to any domain after login.

References

6.5 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.5%