GHSA-mj9r-wwm8-7q52

    Dashboard / Vulnerabilities / GHSA-mj9r-wwm8-7q52

    GHSA-mj9r-wwm8-7q52

    Published: 1 Jul 2021Last Modified: 8 Jul 2026

    Summary: Open Redirect in github.com/AndrewBurian/powermux

    Details: ### Impact Attackers may be able to craft phishing links and other open redirects by exploiting the trailing slash redirection feature. This may lead to users being redirected to untrusted sites after following an attacker crafted link. ### Patches The issue is resolved in v1.1.1 ### Workarounds There are no existing workarounds. You may detect attempts to craft urls that exploit this feature by looking for request paths containing pairs of forward slashes in sequence combined with a trailing slash e.g. `https://example.com//foo/`

    Affected packages

    Package

    Name: github.com/AndrewBurian/powermux

    Purl: pkg:golang/github.com/AndrewBurian/powermux

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.1.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-mj9r-wwm8-7q52 | CVE-DB