CVE-2017-7266
26.03.2017, 05:59
Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain irrespective of the Host header.
Vendor | Product | Version |
---|---|---|
netflix | security_monkey | 𝑥 ≤ 0.7.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References