Uncontrolled external site redirect In drupal/core
Description
Drupal Open Redirect Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulation.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 8.0.4, 7.43, 6.38 | ||
packagist | 6.38, 7.43, 8.0.4 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6.