PT-2021-14438 · Mozilla · Pollbot

Eslamxxx156

·

Published

2021-03-08

·

Updated

2021-03-12

·

CVE-2021-21354

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pollbot versions prior to 1.4.4
Description Pollbot is open source software used to automate polling tasks during the Firefox release process. It contains an open redirection issue in the path of "https://pollbot.services.mozilla.com/". An attacker can exploit this to redirect users to malicious sites by injecting a payload like "//evil.com/" into the URL. For example, typing "https://pollbot.services.mozilla.com//evil.com/" would redirect affected versions to the specified website.
Recommendations To resolve the issue, update to version 1.4.4 or later. As a temporary workaround, consider restricting access to the vulnerable path to minimize the risk of exploitation. Avoid using the vulnerable URL pattern until the issue is resolved.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21354
GHSA-JHGX-WMQ8-JC24

Affected Products

Pollbot