CVE-2024-8412
LinuxOSsk Shakal-NG views.py redirect
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability, which was classified as problematic, was found in LinuxOSsk Shakal-NG up to 1.3.3. Affected is an unknown function of the file comments/views.py. The manipulation of the argument next leads to open redirect. It is possible to launch the attack remotely. The name of the patch is ebd1c2cba59cbac198bf2fd5a10565994d4f02cb. It is recommended to apply a patch to fix this issue.
Es wurde eine Schwachstelle in LinuxOSsk Shakal-NG bis 1.3.3 gefunden. Sie wurde als problematisch eingestuft. Es geht dabei um eine nicht klar definierte Funktion der Datei comments/views.py. Durch das Manipulieren des Arguments next mit unbekannten Daten kann eine open redirect-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk passieren. Der Patch wird als ebd1c2cba59cbac198bf2fd5a10565994d4f02cb bezeichnet. Als bestmögliche Massnahme wird Patching empfohlen.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-09-04 CVE Reserved
- 2024-09-04 CVE Published
- 2024-09-04 CVE Updated
- 2024-09-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://github.com/LinuxOSsk/Shakal-NG/issues/202 | Issue Tracking | |
https://github.com/LinuxOSsk/Shakal-NG/issues/202#issuecomment-2325187434 | Issue Tracking | |
https://vuldb.com/?id.276492 | Technical Description | |
https://vuldb.com/?submit.400792 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/LinuxOSsk/Shakal-NG/commit/ebd1c2cba59cbac198bf2fd5a10565994d4f02cb | 2024-09-04 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
LinuxOSsk Search vendor "LinuxOSsk" | Shakal-NG Search vendor "LinuxOSsk" for product "Shakal-NG" | 1.3.0 Search vendor "LinuxOSsk" for product "Shakal-NG" and version "1.3.0" | en |
Affected
| ||||||
LinuxOSsk Search vendor "LinuxOSsk" | Shakal-NG Search vendor "LinuxOSsk" for product "Shakal-NG" | 1.3.1 Search vendor "LinuxOSsk" for product "Shakal-NG" and version "1.3.1" | en |
Affected
| ||||||
LinuxOSsk Search vendor "LinuxOSsk" | Shakal-NG Search vendor "LinuxOSsk" for product "Shakal-NG" | 1.3.2 Search vendor "LinuxOSsk" for product "Shakal-NG" and version "1.3.2" | en |
Affected
| ||||||
LinuxOSsk Search vendor "LinuxOSsk" | Shakal-NG Search vendor "LinuxOSsk" for product "Shakal-NG" | 1.3.3 Search vendor "LinuxOSsk" for product "Shakal-NG" and version "1.3.3" | en |
Affected
|