VulnerabilityModified
CVE-2017-7266
Netflix Security Monkey before 0.8.0 has an Open Redirect.
MEDIUM 6.1EPSS 0.97%
Does this matter?
Lower severity and a low EPSS score (0.97%). Track it; it rarely justifies an emergency change on its own.
Description
Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain irrespective of the Host header.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- netflix/security monkey
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/97088
- https://github.com/Netflix/security_monkey/commit/3b4da13efabb05970c80f464a50d3c1c12262466Patch, Third Party Advisory
- https://github.com/Netflix/security_monkey/pull/482Third Party Advisory
- https://github.com/Netflix/security_monkey/releases/tag/v0.8.0Release Notes, Third Party Advisory
- http://www.securityfocus.com/bid/97088
- https://github.com/Netflix/security_monkey/commit/3b4da13efabb05970c80f464a50d3c1c12262466Patch, Third Party Advisory
- https://github.com/Netflix/security_monkey/pull/482Third Party Advisory
- https://github.com/Netflix/security_monkey/releases/tag/v0.8.0Release Notes, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.