Uncontrolled external site redirect In symfony/security-http
Description
Symfony Open Redirect
An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the _target_path parameter and generates a redirect response, but no check is performed on the path, which could be an absolute URL to an external domain. This Open redirect vulnerability can be exploited for example to mount effective phishing attacks.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 2.7.38, 2.8.31, 3.2.14, 3.3.13 | ||
packagist | 2.7.38, 2.8.31, 3.2.14, 3.3.13 | ||
debian 13 | 3.4.0+dfsg-1 | ||
packagist | 2.7.38, 2.8.31, 3.2.14, 3.3.13 | ||
debian 11 | 3.4.0+dfsg-1 | ||
debian 12 | 3.4.0+dfsg-1 | ||
debian 14 | 3.4.0+dfsg-1 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4. 5.