漏洞描述
An open redirect vulnerability exists in Rudloff/alltube that could let an attacker construct a URL within the application that causes redirection to an arbitrary external domain via Packagist in versions prior to 3.0.1.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
huntr.devhttps://huntr.dev/bounties/4fb39400-e08b-47af-8c1f-5093c9a51203/↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2022-0692↗huntr.devhttps://huntr.dev/bounties/4fb39400-e08b-47af-8c1f-5093c9a51203↗github.comhttps://github.com/rudloff/alltube/commit/bc14b6e45c766c05757fb607ef8d444cbbfba71a↗github.comhttps://github.com/ARPSyndicate/cvemon↗