Lack of data validation In rdiffweb
Description
rdiffweb vulnerable to Special Element Injection In rdiffweb prior to 2.5.5, lack of sanitisation of characters in SSH key name could allow attacker to inject a hyperlink injection that could allow attacker to redirect victim to malicious websites.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 2.5.5 |
Aliases
1. 2. 3. 4.
References
1. 2. 3.