PT-2022-28065 · Apache · Apache Helix
Everardo Padilla
+1
·
Published
2022-12-19
·
Updated
2022-12-24
·
CVE-2022-47500
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Helix versions 0.8.0 through 1.0.4
Description
The issue is related to a URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the Apache Helix UI component. This vulnerability affects all releases of Apache Helix from 0.8.0 to 1.0.4. The problem was caused by an improperly designed forward component for UI embedding.
Recommendations
For versions 0.8.0 through 1.0.4, upgrade to version 1.1.0 to fix the issue. As a temporary workaround, consider removing the forward component since it was improperly designed for UI embedding.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Helix