Forums | Mahara Community
Security Announcements
/
Security issue relating to incorrect redirect <16.10.7; <17.04.5; <17.10.2
17 January 2018, 17:14
Needing the HTTP Strict Transport Security (HSTS) header when site is https
Vuln type: man-in-the-middle attack
Impact: Redirection to incorrect site
Mahara 16.10 before 16.10.7, 17.04 before 17.04.5 and 17.10 before 17.10.2 using https are vulnerable to users going to incorrect http site.
Reported by: Kirtikumar Anandrao Ramchandani
Bug report: https://bugs.launchpad.net/mahara/+bug/1734767
CVE number: CVE-2017-17455
Edits to this post:
- Kristina Hoeppner - 17 January 2018, 21:03