The Drupal reports that Drupal 7.12 contains the following vulnerability: Unvalidated form redirect CVE: CVE-2012-1589 Drupal core's Form API allows users to set a destination, but failed to validate that the URL was internal to the site. This weakness could be abused to redirect the login to a remote site with a malicious script that harvests the login credentials and redirects to the live site. This vulnerability is mitigated only by the end user's ability to recognize a URL with malicious query parameters to avoid the social engineering required to exploit the problem. External reference: http://drupal.org/node/1557938
Created drupal7 tracking bugs for this issue Affects: fedora-all [bug 956481]
Created drupal7 tracking bugs for this issue Affects: epel-all [bug 956483]