CVE-2024-21641: Flarum's Logout Route allows open redirects

Published Jan 5, 2024
·
Updated

Impact The Flarum /logout route includes a redirect parameter that allows any third party to redirect users from a (trusted) domain of the Flarum installation to redirect to any link. Sample: example.com/logout?return=https://google.com. For logged-in users, the logout must be confirmed. Guests are immediately redirected. This could be used by spammers to redirect to a web address using a trusted domain of a running Flarum installation.

Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526

Patches The vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:

composer update --prefer-dist --no-dev -a -W

You can then confirm you run the latest version using:

composer show flarum/core

Workarounds Some extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5.

References For any questions or comments on this vulnerability, please visit https://discuss.flarum.org/

For support questions, create a discussion at https://discuss.flarum.org/t/support.

A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly.

Other sources

Flarum is open source discussion platform software. Prior to version 1.8.5, the Flarum /logout route includes a redirect parameter that allows any third party to redirect users from a (trusted) domain of the Flarum installation to redirect to any link. For logged-in users, the logout must be confirmed. Guests are immediately redirected. This could be used by spammers to redirect to a web address using a trusted domain of a running Flarum installation. The vulnerability has been fixed and published as flarum/core v1.8.5. As a workaround, some extensions modifying the logout route can remedy this issue if their implementation is safe.

NVD

Affected Software

3 affected componentsFixes available
composer/flarum/framework<1.8.5
1.8.5
composer/flarum/core<1.8.5
1.8.5
Flarum Flarum<1.8.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/flarum/framework to a version that resolves this vulnerability.

    Fixed in 1.8.5
  2. Upgrade

    Upgrade composer/flarum/core to a version that resolves this vulnerability.

    Fixed in 1.8.5
  3. Upgrade

    Upgrade flarum/core to a version that resolves this vulnerability.

    Fixed in 1.8.5
  4. Configuration

    If you cannot upgrade immediately, mitigate the open redirect by ensuring the /logout route’s redirect/return parameter cannot be set to arbitrary external links by untrusted users (e.g., only accept safe/expected post-logout destinations).

    Flarum /logout route return redirect parameter = Do not allow third-party control of /logout?return

Event History

Jan 5, 2024
Advisory Published
via GitHub·08:53 PM
CVE Published
via MITRE·09:02 PM
Data Sourced
via MITRE·09:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-21641?

CVE-2024-21641 is considered a medium severity vulnerability due to the potential for open redirects.

2

How do I fix CVE-2024-21641?

To remediate CVE-2024-21641, upgrade to Flarum version 1.8.5 or later.

3

What is the impact of CVE-2024-21641?

The impact of CVE-2024-21641 is that it allows unauthorized redirection of users after logout from trusted domains.

4

Which versions of Flarum are affected by CVE-2024-21641?

Versions of Flarum prior to 1.8.5 are affected by CVE-2024-21641.

5

What is the nature of the vulnerability in CVE-2024-21641?

CVE-2024-21641 involves an open redirect vulnerability through the logout route which can exploit user trust.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203