CVE-2017-7266

MEDIUM

Netflix Security Monkey <0.8.0 - Open Redirect

Title source: llm
STIX 2.1

Description

Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain irrespective of the Host header.

References (4)

Core 4
Core References
Release Notes, Third Party Advisory x_refsource_confirm
https://github.com/Netflix/security_monkey/releases/tag/v0.8.0
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/97088
Third Party Advisory x_refsource_confirm
https://github.com/Netflix/security_monkey/pull/482

Scores

CVSS v3 6.1
EPSS 0.0096
EPSS Percentile 56.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-601
Status published
Products (2)
netflix/security_monkey < 0.7.0
pypi/security_monkey 0 - 0.8.0PyPI
Published Mar 26, 2017
Tracked Since Feb 18, 2026