CVE-2014-3739: Input Validation
Published May 20, 2014
·Updated
Open redirect vulnerability in zport/aclusers/cookieAuthHelper/loginform in Zenoss 4.2.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the camefrom parameter.
Affected Software
1 affected component
Zenoss Zenoss=4.2.5
Event History
May 20, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3739?
CVE-2014-3739 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2014-3739?
To fix CVE-2014-3739, update Zenoss to a version that is not vulnerable, specifically versions beyond 4.2.5.
3
What kind of attacks can CVE-2014-3739 facilitate?
CVE-2014-3739 can facilitate phishing attacks by allowing attackers to redirect users to arbitrary websites.
4
Which version of Zenoss is affected by CVE-2014-3739?
Zenoss version 4.2.5 is affected by CVE-2014-3739.
5
Where is the vulnerable component located in Zenoss for CVE-2014-3739?
The vulnerable component in Zenoss for CVE-2014-3739 is located in zport/acl_users/cookieAuthHelper/login_form.