PT-2025-12143 · Bentoml · Bentoml

Published

2025-03-20

·

Updated

2025-03-21

·

CVE-2024-12760

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions bentoml/bentoml version 1.3.9
Description An open redirect issue allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.
Recommendations For bentoml/bentoml version 1.3.9, consider validating user-inputted URLs to prevent redirects to unauthorized sites as a temporary workaround. Restrict access to sensitive operations that rely on user-supplied URLs to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-12760
GHSA-564P-RX2Q-4C8V

Affected Products

Bentoml