got (JS Package) <= 11.8.4 and 12.0-<12.1.0 - Open Redirect
2022-06-19 00:00
AnonymousStrategic Overview
StatusPatched in 2.4.3
Affected PluginSimple Page Ordering
Affected Version
<= 2.4.2CVSS5.3Medium
CVE
CVE-2022-33987Vulnerability Overview
The got (JS Package) is vulnerable to Open Redirect in versions up to, and including, 11.8.4 as well as from 12 to below 12.1.0. Requested URLs are not verified and allow open redirection to a local UNIX socket.
Technical Analysis
REMEDIATION: Update to version 2.4.3, or a newer patched version --- IDENTIFIER: CWE-601 (URL Redirection to Untrusted Site ('Open Redirect')) The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C