Vulnerability Description
lorawan-stack is an open source LoRaWAN network server. Prior to version 3.24.1, an open redirect exists on the login page of the lorawan stack server, allowing an attacker to supply a user controlled redirect upon sign in. This issue may allows malicious actors to phish users, as users assume they were redirected to the homepage on login. Version 3.24.1 contains a fix.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Thethingsnetwork | Lorawan-Stack | < 3.24.1 |
Related Weaknesses (CWE)
References
- https://github.com/TheThingsNetwork/lorawan-stack/blob/ecdef730f176c02f7c9afce98Product
- https://github.com/TheThingsNetwork/lorawan-stack/blob/ecdef730f176c02f7c9afce98Product
- https://github.com/TheThingsNetwork/lorawan-stack/commit/f06776028bdb3994847fc60Patch
- https://github.com/TheThingsNetwork/lorawan-stack/releases/tag/v3.24.1Release Notes
- https://securitylab.github.com/advisories/GHSL-2022-138_lorawan-stack/ExploitThird Party Advisory
- https://github.com/TheThingsNetwork/lorawan-stack/blob/ecdef730f176c02f7c9afce98Product
- https://github.com/TheThingsNetwork/lorawan-stack/blob/ecdef730f176c02f7c9afce98Product
- https://github.com/TheThingsNetwork/lorawan-stack/commit/f06776028bdb3994847fc60Patch
- https://github.com/TheThingsNetwork/lorawan-stack/releases/tag/v3.24.1Release Notes
- https://securitylab.github.com/advisories/GHSL-2022-138_lorawan-stack/ExploitThird Party Advisory
FAQ
What is CVE-2023-26494?
CVE-2023-26494 is a vulnerability with a CVSS score of 6.1 (MEDIUM). lorawan-stack is an open source LoRaWAN network server. Prior to version 3.24.1, an open redirect exists on the login page of the lorawan stack server, allowing an attacker to supply a user controlled...
How severe is CVE-2023-26494?
CVE-2023-26494 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-26494?
Check the references section above for vendor advisories and patch information. Affected products include: Thethingsnetwork Lorawan-Stack.