CVE-2020-23015: Medium severity opnsense vulnerability
Published May 3, 2021
·Updated
An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not filtered and can redirect user to any website.
Affected Software
1 affected component
OPNsense OPNsense<=20.1.5
Event History
May 3, 2021
CVE Published
via MITRE·09:32 PM
Data Sourced
via MITRE·09:32 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this open redirect issue?
The vulnerability ID is CVE-2020-23015.
2
What is the severity level of CVE-2020-23015?
The severity level of CVE-2020-23015 is medium.
3
How does CVE-2020-23015 affect OPNsense?
CVE-2020-23015 affects OPNsense version up to and including 20.1.5.
4
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The CWE ID for CVE-2020-23015 is CWE-601.
5
Is there a fix available for CVE-2020-23015?
Yes, the fix for CVE-2020-23015 is available in OPNsense version after 20.1.5.