CVE-2022-0645: Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in posthog/posthog
Published Apr 19, 2022
·Updated
Open redirect vulnerability via endpoint authorizeandredirect/?redirect= in GitHub repository posthog/posthog prior to 1.34.1.
Affected Software
1 affected component
PostHog PostHog<1.34.1
Remediation
Event History
Apr 19, 2022
CVE Published
via MITRE·11:20 AM
Data Sourced
via MITRE·11:20 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-0645.
2
What is the severity of CVE-2022-0645?
The severity of CVE-2022-0645 is medium with a severity value of 6.1.
3
How does the open redirect vulnerability occur in GitHub repository posthog/posthog?
The open redirect vulnerability occurs via the endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to version 1.34.1.
4
Is my version of Posthog affected?
If you are using Posthog version prior to 1.34.1, you are affected by this vulnerability.
5
How can I fix the open redirect vulnerability in Posthog?
To fix the open redirect vulnerability, update your Posthog installation to version 1.34.1 or later.