Date: Sun, 06 Apr 2014 09:57:21 +0200 From: Florian Weimer <fw@...eb.enyo.de> To: oss-security@...ts.openwall.com Subject: CVE request: redmine open redirector Redmine versions 2.4.5 and 2.5.1 fixed an open redirector issue. The code verifying the redirection URIs accepted scheme-relative URIs which can lead to different hosts: http://www.redmine.org/projects/redmine/wiki/Security_Advisories http://www.redmine.org/projects/redmine/wiki/Changelog https://github.com/redmine/redmine/commit/7567c3d8b21fe67e5f04e6839c1fce061600f2f3
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Powered by Openwall GNU/*/Linux - Powered by OpenVZ