PT-2022-28065 · Apache · Apache Helix

Everardo Padilla

+1

·

Published

2022-12-19

·

Updated

2022-12-24

·

CVE-2022-47500

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Helix versions 0.8.0 through 1.0.4
Description The issue is related to a URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the Apache Helix UI component. This vulnerability affects all releases of Apache Helix from 0.8.0 to 1.0.4. The problem was caused by an improperly designed forward component for UI embedding.
Recommendations For versions 0.8.0 through 1.0.4, upgrade to version 1.1.0 to fix the issue. As a temporary workaround, consider removing the forward component since it was improperly designed for UI embedding.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2022-47500
GHSA-MHXG-2XF7-4XWX

Affected Products

Apache Helix