github.com
https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/2018-10-17-2.yaml GHSA-R67R-42WX-C8R7
Drupal External URL injection through URL aliases leading to Open Redirect
Description
The path module in Drupal allows users with the 'administer paths' to create pretty URLs for content. In certain circumstances the user can enter a particular path that triggers an open redirect to a malicious url.
Description source: GitHub Advisory
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
drupal/drupalBrowse Packagist / drupal/drupal | GitHub Advisory | 7.0 to < 7.60 · Fixed in 7.60 | affected |
| 8.0.0 to < 8.5.8 · Fixed in 8.5.8 | affected | ||
| 8.6.0 to < 8.6.2 · Fixed in 8.6.2 | affected |
References
3github.com
https://github.com/drupal/drupal drupal.org
https://www.drupal.org/sa-core-2018-006