RStudio Connect prior to 2023.01.0 is affected by an Open Redirect issue. The vulnerability could allow an attacker to redirect users to malicious websites.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://tenable.com/security/research/tra-2022-30 | third party advisory exploit |
https://support.posit.co/hc/en-us/articles/10983374992023 | third party advisory exploit |