Open Redirect Affecting drupal7 package, versions <7.41-1


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
1.77% (76th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN9-DRUPAL7-404402
  • published18 Oct 2017
  • disclosed18 Oct 2017

Introduced: 18 Oct 2017

CVE-2015-7943  (opens in a new tab)
CWE-601  (opens in a new tab)

How to fix?

Upgrade Debian:9 drupal7 to version 7.41-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream drupal7 package and not the drupal7 package as distributed by Debian. See How to fix? for Debian:9 relevant fixed versions and status.

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3233.