got (JS Package) <= 11.8.4 and 12.0-<12.1.0 - Open Redirect

2022-06-19 00:00
Anonymous

Strategic Overview

Status
Patched in 2.4.3
Affected PluginSimple Page Ordering
Affected Version<= 2.4.2
CVSS5.3Medium
CVECVE-2022-33987
View all Simple Page Ordering vulnerabilities

Vulnerability Overview

The got (JS Package) is vulnerable to Open Redirect in versions up to, and including, 11.8.4 as well as from 12 to below 12.1.0. Requested URLs are not verified and allow open redirection to a local UNIX socket.

Technical Analysis

REMEDIATION: Update to version 2.4.3, or a newer patched version --- IDENTIFIER: CWE-601 (URL Redirection to Untrusted Site ('Open Redirect')) The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C