Lucene search

K
osvGoogleOSV:GHSA-CPGW-2WXR-PWW3
HistoryJun 29, 2021 - 6:32 p.m.

Open Redirect

2021-06-2918:32:39
Google
osv.dev
5

0.001 Low

EPSS

Percentile

48.3%

Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via an initial /\ substring in the user/login redirect_to parameter, related to the function isValidRedirect in routes/user/auth.go.

CPENameOperatorVersion
gogs.io/gogslt0.12.0

0.001 Low

EPSS

Percentile

48.3%

Related for OSV:GHSA-CPGW-2WXR-PWW3