CVE-2017-7266

Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain irrespective of the Host header.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:netflix:security_monkey:*:*:*:*:*:*:*:*

Information

Published : 2017-03-25 22:59

Updated : 2017-03-28 18:59


NVD link : CVE-2017-7266

Mitre link : CVE-2017-7266


JSON object : View

CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

Advertisement

dedicated server usa

Products Affected

netflix

  • security_monkey