
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-4000 is a URL Redirection to Untrusted Site vulnerability affecting the showdoc application. The vulnerability was discovered and disclosed in December 2021, with the initial NVD publication date being December 3, 2021. The vulnerability affects the showdoc software and was reported through the huntr.dev platform (NVD).
The vulnerability has been assigned a CVSS v3.1 Base Score of 6.1 (MEDIUM) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. Additionally, it received a CVSS v2.0 Base Score of 5.8 (MEDIUM) with the vector (AV:N/AC:M/Au:N/C:P/I:P/A:N). The vulnerability is classified under CWE-601: URL Redirection to Untrusted Site ('Open Redirect') (NVD).
The vulnerability allows an attacker to perform URL redirection to untrusted sites. This could potentially lead to unauthorized access to sensitive data and compromise of user security through redirection to malicious websites (NVD).
A fix has been implemented and is available in the showdoc repository. The patch specifically addresses the URL redirection vulnerability by adding additional validation checks for redirect parameters, including checking for the presence of '//' in redirect URLs (Github Patch).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."