We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
When logged in the underlying URL redirection system appears to be open and will will redirect to any requested URL
All open redirects should be denied. While not a direct exploit it can be used as a potential attack surface for misdirection
Include as many relevant details about the environment you experienced the problem in
icinga2 --version
php --version
The text was updated successfully, but these errors were encountered:
login: Don't redirect to external resources
f8ad5c6
fixes #4945
ec7fb82
23aab97
fixes #4945 (cherry picked from commit ec7fb82)
ee43f4a
1c85680
nilmerg
Successfully merging a pull request may close this issue.
Describe the bug
When logged in the underlying URL redirection system appears to be open and will will redirect to any requested URL
To Reproduce
Will issue a 302 redirect to google.com
Expected behavior
All open redirects should be denied. While not a direct exploit it can be used as a potential attack surface for misdirection
Your Environment
Include as many relevant details about the environment you experienced the problem in
icinga2 --version
): r2.13.6-1php --version
): 7.4.3The text was updated successfully, but these errors were encountered: