CVE-2021-32645
Summary
| CVE | CVE-2021-32645 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-27 17:15:00 UTC |
| Updated | 2021-06-08 16:26:00 UTC |
| Description | Tenancy multi-tenant is an open source multi-domain controller for the Laravel web framework. In some situations, it is possible to have open redirects where users can be redirected from your site to any other site using a specially crafted URL. This is only the case for installations where the default Hostname Identification is used and the environment uses tenants that have `force_https` set to `true` (default: `false`). Version 5.7.2 contains the relevant patches to fix this bug. Stripping the URL from special characters to prevent specially crafted URL's from being redirected to. As a work around users can set the `force_https` to every tenant to `false`, however this may degrade connection security. |
Risk And Classification
Problem Types: CWE-601
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tenancy | Multi-tenant | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| hyn/multi-tenant - Packagist | MISC | packagist.org | |
| Trim slashes from request uri before redirecting (#1001) · tenancy/multi-tenant@9c837a2 · GitHub | MISC | github.com | |
| Official Google Webmaster Central Blog: Open redirect URLs: Is your site being abused? | MISC | webmasters.googleblog.com | |
| Open Redirect · Advisory · tenancy/multi-tenant · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.