CVE-2022-38131
RStudio Connect - Open Redirect
Record summary
CVE-2022-38131 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
RStudio Connect prior to 2023.01.0 is affected by an Open Redirect issue. The vulnerability could allow an attacker to redirect users to malicious websites.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
RStudio Connect | CVE List | All versions | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMRStudio Connect - Open RedirectCVSS 6.1
RStudio Connect prior to 2023.01.0 is affected by an Open Redirect issue. The vulnerability could allow an attacker to redirect users to malicious websites.
Impact
An attacker can exploit the vulnerability to redirect users to malicious websites, potentially leading to phishing attacks or other security breaches.
Remediation
This issue is fixed in Connect v2023.05. Additionally, for users running Connect v1.7.2 and later, the issue is resolvable via a configuration setting mentioned in the support article.
Source: ProjectDiscovery