Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS13Mng1LWhwbWctajk4aM4AA0TD
Artesãos SEOTools Open Redirect vulnerability
A vulnerability was found in Artesãos SEOTools up to and including version 0.17.1. This issue affects the function eachValue of the file TwitterCards.php. The manipulation of the argument value leads to open redirect. Upgrading to version 0.17.2 is able to address this issue. The name of the patch is ca27cd0edf917e0bc805227013859b8b5a1f01fb. It is recommended to upgrade the affected component. The identifier VDB-222233 was assigned to this vulnerability.
Permalink: https://github.com/advisories/GHSA-w2x5-hpmg-j98hJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13Mng1LWhwbWctajk4aM4AA0TD
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 10 months ago
Updated: 7 months ago
CVSS Score: 6.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Identifiers: GHSA-w2x5-hpmg-j98h, CVE-2020-36665
References:
- https://nvd.nist.gov/vuln/detail/CVE-2020-36665
- https://github.com/artesaos/seotools/pull/201
- https://github.com/artesaos/seotools/commit/ca27cd0edf917e0bc805227013859b8b5a1f01fb
- https://github.com/artesaos/seotools/releases/tag/v0.17.2
- https://vuldb.com/?ctiid.222233
- https://vuldb.com/?id.222233
- https://github.com/advisories/GHSA-w2x5-hpmg-j98h
Blast Radius: 17.6
Affected Packages
packagist:artesaos/seotools
Dependent packages: 53Dependent repositories: 779
Downloads: 3,253,222 total
Affected Version Ranges: < 0.17.2
Fixed in: 0.17.2
All affected versions: 0.4.1, 0.7.1, 0.7.2, 0.7.3, 0.7.4, 0.8.0, 0.8.1, 0.8.2, 0.9.0, 0.9.1, 0.9.2, 0.10.0, 0.11.1, 0.12.0, 0.12.1, 0.12.2, 0.13.0, 0.14.0, 0.15.0, 0.16.0, 0.17.0, 0.17.1
All unaffected versions: 0.17.2, 0.18.0, 0.19.0, 0.19.1, 0.20.0, 0.20.1, 0.20.2, 0.21.0, 0.22.0, 0.22.1, 0.23.0, 1.0.0, 1.1.0, 1.2.0, 1.3.0