GHSA-4r8q-gv9j-3xx6

    Dashboard / Vulnerabilities / GHSA-4r8q-gv9j-3xx6

    GHSA-4r8q-gv9j-3xx6

    Published: 18 Mar 2022Last Modified: 8 Jul 2026

    Summary: Open Redirect

    Details: ### Impact In some situations, it is possible to have open redirects where users can be redirected from your site to any other site using a specially crafted URL. This is only the case for installations where the default Hostname Identification is used and the environment uses tenants that have `force_https` set to `true` (default: `false`) ### Patches Version 5.7.2 contains the relevant patches to fix this bug. Stripping the URL from special characters to prevent specially crafted URL's from being redirected to. ### Workarounds There is a simple way to work around the security issue - Set the `force_https` to every tenant to `false` ### References https://nvd.nist.gov/vuln/detail/CVE-2018-11784 ### For more information If you have any questions or comments about this advisory: * Contact us in Discord: https://tenancy.dev/chat

    Affected packages

    Package

    Name: hyn/multi-tenant

    Purl: pkg:composer/hyn/multi-tenant

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 5.6.0
    Fixed -5.7.2

    Affected versions

    5.6.0
    5.6.1
    5.6.2
    5.6.3
    5.6.4

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-4r8q-gv9j-3xx6 | CVE-DB