CVE-2017-1000481
Last modified
CVE-2017-1000481 is a vulnerability of currently unknown severity. When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url. After you login, you get redirected to the page you tried to view before. EPSS estimates a 0.69% chance of exploitation in the next 30 days.
Description
When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url. After you login, you get redirected to the page you tried to view before. An attacker might try to abuse this by letting you click on a specially crafted link. You would login, and get redirected to the site of the attacker, letting you think that you are still on the original Plone site. Or some javascript of the attacker could be executed. Most of these types of attacks are already blocked by Plone, using the `isURLInPortal` check to make sure we only redirect to a page on the same Plone site. But a few more ways of tricking Plone into accepting a malicious link were discovered, and fixed with this hotfix.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Plone | Plone | 2.5.5 | — |
| Plone | Plone | 3.3 | — |
| Plone | Plone | 3.3.1 | — |
| Plone | Plone | 3.3.2 | — |
| Plone | Plone | 3.3.3 | — |
| Plone | Plone | 3.3.4 | — |
| Plone | Plone | 3.3.5 | — |
| Plone | Plone | 3.3.6 | — |
| Plone | Plone | 4.0 | — |
| Plone | Plone | 4.0.1 | — |
| Plone | Plone | 4.0.2 | — |
| Plone | Plone | 4.0.3 | — |
| Plone | Plone | 4.0.4 | — |
| Plone | Plone | 4.0.5 | — |
| Plone | Plone | 4.0.7 | — |
| Plone | Plone | 4.0.8 | — |
| Plone | Plone | 4.0.9 | — |
| Plone | Plone | 4.0.10 | — |
| Plone | Plone | 4.1 | — |
| Plone | Plone | 4.1.1 | — |
| Plone | Plone | 4.1.2 | — |
| Plone | Plone | 4.1.3 | — |
| Plone | Plone | 4.1.4 | — |
| Plone | Plone | 4.1.5 | — |
| Plone | Plone | 4.1.6 | — |
| Plone | Plone | 4.2 | — |
| Plone | Plone | 4.2.1 | — |
| Plone | Plone | 4.2.2 | — |
| Plone | Plone | 4.2.3 | — |
| Plone | Plone | 4.2.4 | — |
| Plone | Plone | 4.2.5 | — |
| Plone | Plone | 4.2.6 | — |
| Plone | Plone | 4.2.7 | — |
| Plone | Plone | 4.3 | — |
| Plone | Plone | 4.3.1 | — |
| Plone | Plone | 4.3.2 | — |
| Plone | Plone | 4.3.3 | — |
| Plone | Plone | 4.3.4 | — |
| Plone | Plone | 4.3.5 | — |
| Plone | Plone | 4.3.6 | — |
| Plone | Plone | 4.3.7 | — |
| Plone | Plone | 4.3.8 | — |
| Plone | Plone | 4.3.9 | — |
| Plone | Plone | 4.3.10 | — |
| Plone | Plone | 4.3.11 | — |
| Plone | Plone | 4.3.12 | — |
| Plone | Plone | 4.3.14 | — |
| Plone | Plone | 4.3.15 | — |
| Plone | Plone | 5.0 | — |
| Plone | Plone | 5.0.1 | — |
Showing 50 of 59 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-1000481?
How severe is CVE-2017-1000481?
How do I fix CVE-2017-1000481?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-1000475FreeSSHd 1.3.1 version is vulnerable to an Unquoted Path Ser…
- CVE-2017-1000476ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability was…
- CVE-2017-1000477XMLBundle version 0.1.7 is vulnerable to XXE attacks which c…
- CVE-2017-1000478ELabftw version 1.7.8 is vulnerable to stored cross-site scr…
- CVE-2017-1000479pfSense versions 2.4.1 and lower are vulnerable to clickjack…
- CVE-2017-1000480Smarty 3 before 3.1.32 is vulnerable to a PHP code injection…
- CVE-2017-1000482A member of the Plone 2.5-5.1rc1 site could set javascript i…
- CVE-2017-1000483Accessing private content via str.format in through-the-web …
- CVE-2017-1000484By linking to a specific url in Plone 2.5-5.1rc1 with a para…
- CVE-2017-1000485Nylas Mail Lives 2.2.2 uses 0755 permissions for $HOME/.nyla…
- CVE-2017-1000486Primetek Primefaces 5.x is vulnerable to a weak encryption f…9.8
- CVE-2017-1000487Plexus-utils before 3.0.16 is vulnerable to command injectio…9.8
Are you affected by CVE-2017-1000481?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
