[wp-trac] [WordPress Trac] #47980: New wp_validate_redirect() removes domain in some circumstances.

WordPress Trac noreply at wordpress.org
Fri Sep 27 18:20:04 UTC 2019


#47980: New wp_validate_redirect() removes domain in some circumstances.
--------------------------+-----------------------------
 Reporter:  rconde        |       Owner:  SergeyBiryukov
     Type:  defect (bug)  |      Status:  assigned
 Priority:  normal        |   Milestone:  5.2.4
Component:  General       |     Version:  5.2.3
 Severity:  critical      |  Resolution:
 Keywords:  has-patch     |     Focuses:
--------------------------+-----------------------------

Comment (by daxelrod):

 Noting the original commit which caused this bug was to fix a security
 issue: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16220

 It would be useful to know what circumstances could lead to an open
 redirect to ensure a patch for this bug doesn't cause a regression.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/47980#comment:19>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list