Skip to content

Open redirect in Mozilla WebThings Gateway

Moderate
mrstegeman published GHSA-jh29-8vm9-rrqc Apr 27, 2020

Package

WebThings Gateway

Affected versions

>= 0.3.0, < 0.12.0

Patched versions

0.12.0

Description

Impact

An open redirect is present on the gateway's login page, which could cause a user to be redirected to a malicious site after logging in.

Patches

The issue has been patched in 0.12.0.

#2446

Workarounds

  • Never share your gateway address publicly.
  • Never click on links which take you to your gateway, especially to the login page.

Severity

Moderate

CVE ID

CVE-2020-6803

Weaknesses

No CWEs