Autobahn|Python before 20.12.3 allows redirect header injection.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://github.com/crossbario/autobahn-python | third party advisory product |
https://github.com/crossbario/autobahn-python/compare/v20.12.2...v20.12.3 | third party advisory patch |
https://pypi.org/project/autobahn/20.12.3/ | third party advisory product |
https://autobahn.readthedocs.io/en/latest/changelog.html | release notes vendor advisory |
https://github.com/crossbario/autobahn-python/pull/1439 | third party advisory patch |