Open Redirect Vulnerability in LabKey Server Community Edition
CVE-2019-3912

6.1MEDIUM

Key Information:

Vendor

Tenable

Vendor
CVE Published:
30 January 2019

What is CVE-2019-3912?

A security flaw exists in the LabKey Server Community Edition before version 18.3.0-61806.763, which allows an unauthenticated attacker to exploit the /__r1/ returnURL parameter leading to open redirection. This vulnerability can enable malicious users to redirect unsuspecting individuals to arbitrary and potentially harmful websites, posing significant risks to users' data security and privacy.

Affected Version(s)

LabKey Server Community Edition Versions before 18.3.0-61806.763

References

EPSS Score

16% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.