### Impact A url `/login?came_from=////evil.example` may redirect to an external website after login. Standard Plone is not affected, but if you have customised the login, for example with add-ons, you might be affected. You can try the url to check if you are affected or not. ### Patches The problem has been patched in `Products.isurlinportal`. * Plone 6.2: upgrade to `Products.isurlinportal` 4.0.0. * Plone 6.1: upgrade to `Products.isurlinportal` 3.1.0. * Plone 6.0: upgrade to `Products.isurlinportal` 2.1.0. * Older Plone versions don't have security support anymore. ### Workarounds There are no known workarounds. ### Background When you are anonymous and land on a page that requires a login, Plone sends you to the login form. After successful login, Plone redirects you back to the page you came from. Various other forms and pages have a similar system. This could get abused by an attacker to trick Plone into redirecting to a different website. Plone checks the page that would be redirected to. It is only accepted if it is within the Plone site domain or part of a different trusted domain. The main check for this is in the `Products.isurlinportal` package. A lot of potentially malicious urls are already safely rejected, but here a loop hole was found. This was discovered during a penetration test by the CERT-EU Team.
### Impact A url `/login?came_from=////evil.example` may redirect to an external website after login. Standard Plone is not affected, but if you have customised the login, for example with add-ons, you might be affected. You can try the url to check if you are affected or not. ### Patches The problem has been patched in `Products.isurlinportal`. * Plone 6.2: upgrade to `Products.isurlinportal` 4.0.0. * Plone 6.1: upgrade to `Products.isurlinportal` 3.1.0. * Plone 6.0: upgrade to `Products.isurlinportal` 2.1.0. * Older Plone versions don't have security support anymore. ### Workarounds There are no known workarounds. ### Background When you are anonymous and land on a page that requires a login, Plone sends you to the login form. After successful login, Plone redirects you back to the page you came from. Various other forms and pages have a similar system. This could get abused by an attacker to trick Plone into redirecting to a different website. Plone checks the page that would be redirected to. It is only accepted if it is within the Plone site domain or part of a different trusted domain. The main check for this is in the `Products.isurlinportal` package. A lot of potentially malicious urls are already safely rejected, but here a loop hole was found. This was discovered during a penetration test by the CERT-EU Team.
Update products-isurlinportal to 2.1.0; products-isurlinportal to 3.1.0; Products.isurlinportal to 4.0.0; Products.isurlinportal to 3.1.0; Products.isurlinportal to 2.1.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanProducts.isurlinportal has possible open redirect when using more than 2 forward slashes affects products-isurlinportal (pip), products-isurlinportal (pip), Products.isurlinportal (pip), Products.isurlinportal (pip), Products.isurlinportal (pip). Severity is medium. ### Impact A url `/login?came_from=////evil.example` may redirect to an external website after login. Standard Plone is not affected, but if you have customised the login, for example with add-ons, you might be affected. You can try the url to check if you are affected or not. ### Patches The problem has been patched in `Products.isurlinportal`. * Plone 6.2: upgrade to `Products.isurlinportal` 4.0.0. * Plone 6.1: upgrade to `Products.isurlinportal` 3.1.0. * Plone 6.0: upgrade to `Products.isurlinportal` 2.1.0. * Older Plone versions don't have security support anymore. ### Workarounds There are no known workarounds. ### Background When you are anonymous and land on a page that requires a login, Plone sends you to the login form. After successful login, Plone redirects you back to the page you came from. Various other forms and pages have a similar system. This could get abused by an attacker to trick Plone into redirecting to a different website. Plone checks the page that would be redirected to. It is only accepted if it is within the Plone site domain or part of a different trusted domain. The main check for this is in the `Products.isurlinportal` package. A lot of potentially malicious urls are already safely rejected, but here a loop hole was found. This was discovered during a penetration test by the CERT-EU Team.
AI coding agents often install or upgrade packages automatically in pip. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| products-isurlinportalpip | >=0,<2.1.0 | 2.1.0 |
| products-isurlinportalpip | >=3.0.0,<3.1.0 | 3.1.0 |
| Products.isurlinportalpip | =4.0.0a1 | 4.0.0 |
| Products.isurlinportalpip | >=3.0.0,<3.1.0 | 3.1.0 |
| Products.isurlinportalpip | <2.1.0 | 2.1.0 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate products-isurlinportal to 2.1.0; products-isurlinportal to 3.1.0; Products.isurlinportal to 4.0.0; Products.isurlinportal to 3.1.0; Products.isurlinportal to 2.1.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanProducts.isurlinportal has possible open redirect when using more than 2 forward slashes affects products-isurlinportal (pip), products-isurlinportal (pip), Products.isurlinportal (pip), Products.isurlinportal (pip), Products.isurlinportal (pip). Severity is medium. ### Impact A url `/login?came_from=////evil.example` may redirect to an external website after login. Standard Plone is not affected, but if you have customised the login, for example with add-ons, you might be affected. You can try the url to check if you are affected or not. ### Patches The problem has been patched in `Products.isurlinportal`. * Plone 6.2: upgrade to `Products.isurlinportal` 4.0.0. * Plone 6.1: upgrade to `Products.isurlinportal` 3.1.0. * Plone 6.0: upgrade to `Products.isurlinportal` 2.1.0. * Older Plone versions don't have security support anymore. ### Workarounds There are no known workarounds. ### Background When you are anonymous and land on a page that requires a login, Plone sends you to the login form. After successful login, Plone redirects you back to the page you came from. Various other forms and pages have a similar system. This could get abused by an attacker to trick Plone into redirecting to a different website. Plone checks the page that would be redirected to. It is only accepted if it is within the Plone site domain or part of a different trusted domain. The main check for this is in the `Products.isurlinportal` package. A lot of potentially malicious urls are already safely rejected, but here a loop hole was found. This was discovered during a penetration test by the CERT-EU Team.
AI coding agents often install or upgrade packages automatically in pip. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| products-isurlinportalpip | >=0,<2.1.0 | 2.1.0 |
| products-isurlinportalpip | >=3.0.0,<3.1.0 | 3.1.0 |
| Products.isurlinportalpip | =4.0.0a1 | 4.0.0 |
| Products.isurlinportalpip | >=3.0.0,<3.1.0 | 3.1.0 |
| Products.isurlinportalpip | <2.1.0 | 2.1.0 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard