PT-2021-14438 · Mozilla · Pollbot
Eslamxxx156
·
Published
2021-03-08
·
Updated
2021-03-12
·
CVE-2021-21354
CVSS v3.1
7.4
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Pollbot versions prior to 1.4.4
Description
Pollbot is open source software used to automate polling tasks during the Firefox release process. It contains an open redirection issue in the path of "https://pollbot.services.mozilla.com/". An attacker can exploit this to redirect users to malicious sites by injecting a payload like "//evil.com/" into the URL. For example, typing "https://pollbot.services.mozilla.com//evil.com/" would redirect affected versions to the specified website.
Recommendations
To resolve the issue, update to version 1.4.4 or later. As a temporary workaround, consider restricting access to the vulnerable path to minimize the risk of exploitation. Avoid using the vulnerable URL pattern until the issue is resolved.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pollbot