Red Hat Bugzilla – Bug 1373440
CVE-2016-7137 plone: Open Redirection in Plone
Last modified: 2016-09-06 07:15:09 EDT
It was discovered that in multiple places, Plone blindly uses the referer header to redirect a user to the next page after a particular action. An attacker could utilize this to draw a user into a redirection attack. CVE assignment: http://seclists.org/oss-sec/2016/q3/417 External References: https://plone.org/security/hotfix/20160830/open-redirection-in-plone
Created plone tracking bugs for this issue: Affects: epel-5 [bug 1373467]