漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
URL Redirection to Untrusted Site ('Open Redirect') in Products.PluggableAuthService
Vulnerability Description
Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 there is an open redirect vulnerability. A maliciously crafted link to the login form and login functionality could redirect the browser to a different website. The problem has been fixed in version 2.6.1. Depending on how you have installed Products.PluggableAuthService, you should change the buildout version pin to `2.6.1` and re-run the buildout, or if you used `pip` simply do `pip install "Products.PluggableAuthService>=2.6.1".
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Vulnerability Type
指向未可信站点的URL重定向(开放重定向)
Vulnerability Title
Jens Vagelpohl Products.PluggableAuthService 输入验证错误漏洞
Vulnerability Description
Jens Vagelpohl Products.PluggableAuthService是 (Jens Vagelpohl)开源的一个应用程序。该产品定义了一个可完全插入的用户文件夹,供所有Zope网站使用。 Products.PluggableAuthService before version 2.6.0 存在安全漏洞,该漏洞源于一个打开的重定向漏洞。恶意制作的登录表单和登录功能链接可能会将浏览器重定向到另一个网站。
CVSS Information
N/A
Vulnerability Type
N/A