CVE-2022-1254: SWG URL redirection vulnerability
A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to 8.2.27, and 7.x prior to 7.8.2.31, and controlled release 11.x prior to 11.1.3 allows a remote attacker to redirect a user to a malicious website controlled by the attacker. This is possible because SWG incorrectly creates a HTTP redirect response when a user clicks a carefully constructed URL. Following the redirect response, the new request is still filtered by the SWG policy.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-1254?
CVE-2022-1254 is a URL redirection vulnerability in Skyhigh SWG that allows a remote attacker to redirect a user to a malicious website.
Which versions of Skyhigh SWG are affected by CVE-2022-1254?
Main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to 8.2.27, and 7.x prior to 7.8.2.31, and controlled release 11.x prior to 11.1.3 of Skyhigh SWG are affected.
How severe is CVE-2022-1254?
CVE-2022-1254 has a severity rating of 6.1, which is considered medium.
How can an attacker exploit CVE-2022-1254?
An attacker can exploit CVE-2022-1254 by redirecting a user to a malicious website controlled by the attacker.
How can I fix CVE-2022-1254?
To fix CVE-2022-1254, update Skyhigh SWG to the latest version, which is 10.2.9 for main releases, 9.2.20 for 9.x releases, 8.2.27 for 8.x releases, 7.8.2.31 for 7.x releases, and 11.1.3 for controlled releases.