
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (GHSA-w228-rfpx-fhm4) is an Open Redirect vulnerability discovered in the cg package (pip), affecting versions <= 60.2.6. The issue was identified in the handling of the referrer header in the application and was patched in version 60.2.12. The vulnerability was published and reviewed on April 23, 2024 (GitHub Advisory).
The vulnerability stems from improper validation of the referrer header in certain conditions within the application. The specific issue was identified in the invoice view functionality at cg/server/invoices/views.py line 173, where the application directly uses the referrer header for redirection without proper validation. The vulnerability has been assigned a CVSS v3.1 base score of 6.1 (Moderate severity) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N (GitHub Advisory).
The exploitation of this vulnerability could enable attackers to redirect users to malicious websites or phishing pages, potentially leading to the disclosure of sensitive information. The impact includes possible phishing attacks, malware distribution, and potential exploitation of other vulnerabilities (GitHub Advisory).
The vulnerability is exploitable by manipulating the referer header in HTTP requests. An attacker can modify the referer header to redirect users to arbitrary domains without any verification. The attack requires no special privileges but does need user interaction (GitHub Advisory).
The vulnerability has been patched in version 60.2.12 of the cg package. Users should upgrade to this version or later to mitigate the risk (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."