First published: Thu Dec 26 2019(Updated: )
Open redirect vulnerability in Athenz v1.8.24 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted page.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Yahoo Athenz | <=1.8.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6035 is an open redirect vulnerability in Athenz v1.8.24 and earlier.
CVE-2019-6035 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks.
CVE-2019-6035 has a severity rating of 6.1, which is considered medium.
To fix CVE-2019-6035, upgrade to the latest version of Athenz (v1.8.25 or later) which includes a patch for the vulnerability.
You can find more information about CVE-2019-6035 at the following references: [JVN website](http://jvn.jp/en/jp/JVN57070811/index.html), [Athenz GitHub repository](https://github.com/yahoo/athenz), [Athenz pull request](https://github.com/yahoo/athenz/pull/700).