Oval Definition:oval:com.ubuntu.artful:def:201716652000
Revision Date:2018-06-13Version:1
Title:CVE-2017-16652 on Ubuntu 17.10 (artful) - medium.
Description:An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the _target_path parameter and generates a redirect response, but no check is performed on the path, which could be an absolute URL to an external domain. This Open redirect vulnerability can be exploited for example to mount effective phishing attacks.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2017-16652
Platform(s):Ubuntu 17.10
Product(s):
Definition Synopsis
  • Ubuntu 17.10 (artful) is installed.
  • AND The vulnerability of the 'symfony' package in artful is not known (status: 'needs-triage'). It is pending evaluation.
  • BACK