SickChill is an automatic video library manager for TV shows. A user-controlled `login` endpoint's `next_` parameter takes arbitrary content. Prior to commit c7128a8946c3701df95c285810eb75b2de18bf82, an authenticated attacker may use this to redirect the user to arbitrary destinations, leading to open redirect. Commit c7128a8946c3701df95c285810eb75b2de18bf82 changes the login page to redirect to `settings.DEFAULT_PAGE` instead of to the `next` parameter.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Jan 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SickChill is an automatic video library manager for TV shows. A user-controlled `login` endpoint's `next_` parameter takes arbitrary content. Prior to commit c7128a8946c3701df95c285810eb75b2de18bf82, an authenticated attacker may use this to redirect the user to arbitrary destinations, leading to open redirect. Commit c7128a8946c3701df95c285810eb75b2de18bf82 changes the login page to redirect to `settings.DEFAULT_PAGE` instead of to the `next` parameter. | |
Title | GHSL-2024-288: SickChill open redirect in login | |
Weaknesses | CWE-601 | |
References |
|
|
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-01-08T20:44:53.785Z
Updated: 2025-01-08T20:44:53.785Z
Reserved: 2024-11-25T23:14:36.382Z
Link: CVE-2024-53995
Vulnrichment
No data.
NVD
Status : Received
Published: 2025-01-08T21:15:12.703
Modified: 2025-01-08T21:15:12.703
Link: CVE-2024-53995
Redhat
No data.