ZeroHour

CVE-2017-7266

CVSS 3.0
6.1 medium
EPSS
<1%p60
Published
()
Modified
Description

Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain irrespective of the Host header.

Vendors
netflix
Products
security monkey
Weakness
CWE-601
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.