CVE-2022-0692 – rudloff/alltube
Package
Manager: composer
Name: rudloff/alltube
Vulnerable Version: >=0 <3.0.1
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
EPSS: 0.20834 pctl0.95394
Details
Open Redirect in AllTube ### Impact Releases prior to 3.0.1 are vulnerable to an open redirect vulnerability that allows an attacker to construct a URL that redirects to an arbitrary external domain. ### Patches 3.0.1 contains a fix for this vulnerability. (The 1.x and 2.x releases are not maintained anymore.) ### References * https://github.com/rudloff/alltube/commit/bc14b6e45c766c05757fb607ef8d444cbbfba71a * https://huntr.dev/bounties/4fb39400-e08b-47af-8c1f-5093c9a51203/ * https://nvd.nist.gov/vuln/detail/CVE-2022-0692
Metadata
Created: 2022-02-23T21:15:01Z
Modified: 2022-03-02T21:07:57Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-jmhf-9fj8-88gh/GHSA-jmhf-9fj8-88gh.json
CWE IDs: ["CWE-601"]
Alternative ID: GHSA-jmhf-9fj8-88gh
Finding: F156
Auto approve: 1