Junglewise Threat Intelligence

CVE-2021-4260: Oils JS open redirect in core/Web.js

CVE-2021-4260 · Severity: low · CVSS 3.1 · Published 2022-12-19

Vendors: npm.

Executive brief

Oils JS is a JavaScript library used for web application development. An open redirect vulnerability in the core/Web.js component allows attackers to redirect users to arbitrary external websites, potentially leading to phishing attacks or credential theft when users are tricked into following malicious links.

Technical details

An open redirect vulnerability (CWE-601) exists in oils-js core/Web.js component. The vulnerability allows manipulation of redirect logic to point to arbitrary external URLs. The attack requires network access and user authentication (PR:L per CVSS). An attacker can craft a malicious request to redirect authenticated users to arbitrary external websites, potentially facilitating phishing or credential harvesting attacks. The vulnerability was fixed in version 8.0.0 via commit fad8fbae824a7d367dacb90d56cb02c5cb999d42.

Affected products

  • Manny Vergel oils before 8.0.0

Timeline

  • 2022-12-19: disclosed
  • 2022-12-19: patched: Fixed in version 8.0.0

References