Some Eclipse Foundation services are deprecated, or will be soon. Please ensure you've read this important communication.

Bug 517030

Summary: Open redirects on https://accounts.eclipse.org
Product: Community Reporter: <"xss' <"xss' <strukt93>
Component: Vulnerability ReportsAssignee: Security vulnerabilitied reported against Eclipse projects <vulnerability.reports-inbox>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: P3 CC: chris.guindon, wayne.beaton
Version: unspecified   
Target Milestone: ---   
Hardware: PC   
OS: Windows 7   
Whiteboard:

Description <"xss' <"xss' CLA 2017-05-21 07:19:43 EDT
Hello,

There's an open redirects vulnerability on the mentioned subdomain upon logging in. This allows attackers to redirect users to malicious places on the internet on your behalf and perform further attacks against them.

Visit https://accounts.eclipse.org/user/login/?takemeback=//example.com and login with your credentials, notice that you have been redirected to example.com as a PoC.

Regards,
Comment 1 Christopher Guindon CLA 2017-06-05 12:14:57 EDT
Making this a "Committer-only group for handling security advisories in a closed fashion".
Comment 2 Christopher Guindon CLA 2017-06-05 16:43:00 EDT
(In reply to <"xss' <"xss' from comment #0)
> Hello,
> 
> There's an open redirects vulnerability on the mentioned subdomain upon
> logging in. This allows attackers to redirect users to malicious places on
> the internet on your behalf and perform further attacks against them.
> 
> Visit https://accounts.eclipse.org/user/login/?takemeback=//example.com and
> login with your credentials, notice that you have been redirected to
> example.com as a PoC.
> 
> Regards,

I have a patch submitted for this. I am hoping we can get this fix on production in the next day or so.
Comment 3 Christopher Guindon CLA 2017-06-08 17:17:37 EDT
(In reply to Christopher Guindon from comment #2)
> (In reply to <"xss' <"xss' from comment #0)
> > Hello,
> > 
> > There's an open redirects vulnerability on the mentioned subdomain upon
> > logging in. This allows attackers to redirect users to malicious places on
> > the internet on your behalf and perform further attacks against them.
> > 
> > Visit https://accounts.eclipse.org/user/login/?takemeback=//example.com and
> > login with your credentials, notice that you have been redirected to
> > example.com as a PoC.
> > 
> > Regards,
> 
> I have a patch submitted for this. I am hoping we can get this fix on
> production in the next day or so.

This is now on production!

Thanks for the bug report!