PT-2022-5023 · Rdiffweb · Rdiffweb

Published

2022-10-10

·

Updated

2022-10-11

·

CVE-2022-3438

CVSS v2.0

8.7

High

VectorAV:N/AC:L/Au:S/C:P/I:C/A:C
Name of the Vulnerable Software and Affected Versions rdiffweb versions prior to 2.5.0a4
Description The issue is related to an open redirect vulnerability in the web interface of rdiff-backup Rdiffweb. This vulnerability allows a remote attacker to redirect users to an arbitrary URL by exploiting a lack of user input validation.
Recommendations For versions prior to 2.5.0a4, update to version 2.5.0a4 or later to resolve the issue. As a temporary workaround, consider implementing additional user input validation to prevent open redirects until a patch is applied. Restrict access to the web interface to minimize the risk of exploitation.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06236
CVE-2022-3438
GHSA-8G9M-VV69-7J99
PYSEC-2022-43158

Affected Products

Rdiffweb