Anubis, Open Redirect Vulnerability, CVE-2021-21277 (Medium)

Listen to this Post

The CVE-2021-21277 vulnerability exists within the subrequest authentication mechanism of the Anubis software. The flaw is an open redirect that occurs because the application does not properly validate or sanitize the user-supplied value in the ‘redir’ URL parameter before incorporating it into a redirect response. When a request is made to a vulnerable endpoint, such as /.within.website/, the application takes the `redir` parameter’s value and uses it directly in the `Location` HTTP header. This allows an attacker to craft a URL that causes the server to respond with a redirect to an arbitrary, attacker-controlled location, including dangerous URL schemes like javascript:. While modern browsers typically block redirects to the `javascript:` scheme for security reasons, this behavior can still be exploited to redirect users to custom protocols associated with third-party applications, potentially leading to harmful actions on the user’s system.
Platform: Anubis
Version: Pre 1.0
Vulnerability: Open Redirect
Severity: Medium
date: 2021-01-19

Prediction: 2021-02-16

What Undercode Say:

curl -I "https://vulnerable.example.com/.within.website/?redir=javascript:alert('XSS')"
grep -r "redir" /app/anubis/source_code/
Hypothetical vulnerable code snippet
redirect_url = request.GET.get('redir')
return HttpResponseRedirect(redirect_url)

How Exploit:

Attacker sends a crafted link with a malicious `redir` parameter. User clicks, and the server’s redirect response attempts to execute a script or open a local application protocol handler.

Protection from this CVE:

Validate redirect URLs.

Whitelist allowed URL schemes.

Use relative paths for redirects.

Impact:

User redirection to malicious sites.

Potential protocol handler abuse.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top