CVE-2024-28113

low

Description

Peering Manager is a BGP session management tool. In Peering Manager <=1.8.2, it is possible to redirect users to an arbitrary page using a crafted url. As a result users can be redirected to an unexpected location. This issue has been addressed in version 1.8.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.

References

https://github.com/peering-manager/peering-manager/security/advisories/GHSA-f4mf-5g28-q7f5

https://github.com/peering-manager/peering-manager/commit/49dc5593184d7740d81e57dbbe3f971d2969dfac

Details

Source: Mitre, NVD

Published: 2024-03-12

Updated: 2024-03-13

CVSS v3

Base Score: 3.5

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N

Severity: Low