Uncontrolled external site redirect In django-allauth
Description
django-allauth has an open redirect vulnerability An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled (it is disabled by default), which may allow an attacker to redirect users to an arbitrary external website via a crafted URL.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | - | ||
debian 12 | - | ||
pypi | 65.14.1 | ||
debian 13 | - | ||
debian 14 | 65.15.0-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3.