CVE-2020-25846

CVSS v3 Score
7.4
High
CVSS v2 Score
4.3
Medium

Vulnerability Description

The digest generation function of NHIServiSignAdapter has not been verified for source file path, which leads to the SMB request being redirected to a malicious host, resulting in the leakage of user's credential.

CVSS:7.4(High)

Multiple open redirect vulnerabilities in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.30 and 1.7.x before 1.7.8 allow remote attackers to redirect users to arbitrary web sites and conduct p...

CVSS:7.4(High)

flask-oidc version 0.1.2 and earlier is vulnerable to an open redirect

CVSS:7.4(High)

An issue was discovered in Open-Xchange OX AppSuite before 7.8.0-rev27. The "defer" servlet offers to redirect a client to a specified URL. Since some checks were missing, arbitrary URLs could be prov...

CVSS:7.4(High)

An open redirect vulnerability has been detected with some Pivotal Cloud Foundry Elastic Runtime components. Users of affected versions should apply the following mitigation: Upgrade PCF Elastic Runti...

CVSS:7.4(High)

cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).

CVSS:7.4(High)

Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.