CVE-2017-16652
symfony - security update
6.1
MEDIUM
CVSS 3.1
EPSS 0.95%
描述
An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the _target_path parameter and generates a redirect response, but no check is performed on the path, which could be an absolute URL to an external domain. This Open redirect vulnerability can be exploited for example to mount effective phishing attacks.
如何修補 CVE-2017-16652
要修補 CVE-2017-16652,請將受影響套件升級到下列已修補版本。
- —升級至 3.4.0+dfsg-1 或更新版本
- —升級至 2.3.21+dfsg-4+deb8u4 或更新版本
- —升級至 2.7.38 或更新版本
- —升級至 2.7.38 或更新版本
- —升級至 2.7.38 或更新版本
CVE-2017-16652 正在被利用嗎?
低 — EPSS 為 0.9%,目前沒有觀察到大規模利用活動。
受影響套件(5)
- from 0, < 3.4.0+dfsg-1
- from 0, < 2.3.21+dfsg-4+deb8u4
- >= 2.7.0, < 2.7.38
- >= 2.7.0, < 2.7.38
- >= 2.7.0, < 2.7.38
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |