First published: Mon May 03 2021(Updated: )
An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not filtered and can redirect user to any website.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OPNsense | <=20.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-23015.
The severity level of CVE-2020-23015 is medium.
CVE-2020-23015 affects OPNsense version up to and including 20.1.5.
The CWE ID for CVE-2020-23015 is CWE-601.
Yes, the fix for CVE-2020-23015 is available in OPNsense version after 20.1.5.