GHSA-rcmj-xp8f-f6q4

Suggest an improvement
Source
https://github.com/advisories/GHSA-rcmj-xp8f-f6q4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rcmj-xp8f-f6q4/GHSA-rcmj-xp8f-f6q4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rcmj-xp8f-f6q4
Aliases
Published
2022-05-01T23:55:06Z
Modified
2024-11-18T21:09:24.957198Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Trac Open redirect vulnerability
Details

Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter, possibly related to the quickjump function.

References

Affected packages

PyPI / trac

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.10.5

Affected versions

0.*

0.8.4
0.9
0.10