CVE-2017-1000163: Medium severity phoenixframework phoenix vulnerability

Published Nov 17, 2017
·
Updated

The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, which may result in phishing or social engineering attacks.

Other sources

The Phoenix team designed Phoenix.Controller.redirect/2 to protect against redirects allowing user input to redirect to an external URL where your application code otherwise assumes a local path redirect. This is why the :to option is used for “local” URL redirects and why you must pass the :external option to intentionally allow external URLs to be redirected to. It has been disclosed that carefully crafted user input may be treated by some browsers as an external URL. An attacker can use this vulnerability to aid in social engineering attacks. The most common use would be to create highly believable phishing attacks. For example, the following user input would pass local URL validation, but be treated by Chrome and Firefox as external URLs: http://localhost:4000/?redirect=/\nexample.com Not all browsers are affected, but latest Chrome and Firefox will issue a get request for example.com and successfully redirect externally

Affected Software

18 affected componentsFixes available
erlang/phoenix>=1.2.0<1.2.3
1.2.3
erlang/phoenix>=1.1.0<1.1.8
1.1.8
erlang/phoenix<1.0.6
1.0.6
phoenixframework phoenix=1.0.0
phoenixframework phoenix=1.0.1
phoenixframework phoenix=1.0.2
phoenixframework phoenix=1.0.3
phoenixframework phoenix=1.0.4
phoenixframework phoenix=1.1.0
phoenixframework phoenix=1.1.1
phoenixframework phoenix=1.1.2
phoenixframework phoenix=1.1.3
phoenixframework phoenix=1.1.4
phoenixframework phoenix=1.1.5
phoenixframework phoenix=1.1.6
phoenixframework phoenix=1.2.0
phoenixframework phoenix=1.2.2
phoenixframework phoenix=1.3.0-rc.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade erlang/phoenix to a version that resolves this vulnerability.

    Fixed in 1.2.3
  2. Upgrade

    Upgrade erlang/phoenix to a version that resolves this vulnerability.

    Fixed in 1.1.8
  3. Upgrade

    Upgrade erlang/phoenix to a version that resolves this vulnerability.

    Fixed in 1.0.6
  4. Configuration

    When using `Phoenix.Controller.redirect/2`, ensure user-controlled redirects use the `:to` option for local URL paths and do NOT pass the `:external` option unless you intentionally want to allow external URLs (i.e., avoid allowing inputs that would redirect externally, such as payloads containing `/\nexample.com`).

    Phoenix Framework (Phoenix.Controller.redirect/2) :external option for redirects (:to vs external) = Require default local redirect; only set :external => true when external URLs must be allowed

Event History

Nov 17, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Apr 12, 2022
Advisory Published
09:16 PM

Frequently Asked Questions

1

What is the severity of CVE-2017-1000163?

CVE-2017-1000163 is classified as a medium severity vulnerability due to the potential for phishing and social engineering attacks.

2

How do I fix CVE-2017-1000163?

To resolve CVE-2017-1000163, upgrade the Phoenix Framework to version 1.2.3, 1.1.8, or 1.0.6, depending on your current version.

3

What versions are affected by CVE-2017-1000163?

CVE-2017-1000163 affects Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2, and 1.3.0-rc.0.

4

What type of vulnerability is CVE-2017-1000163?

CVE-2017-1000163 is an unvalidated URL redirection vulnerability.

5

Can CVE-2017-1000163 lead to other attacks?

Yes, CVE-2017-1000163 can potentially facilitate phishing and social engineering attacks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203