{"id":"CVE-2021-21337","aliases":["GHSA-p44j-xrqg-4xrr","PYSEC-2021-45"],"url":"https://o3.security/vulnerability/CVE-2021-21337","summary":"URL Redirection to Untrusted Site ('Open Redirect') in Products.PluggableAuthService","details":"Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 there is an open redirect vulnerability. A maliciously crafted link to the login form and login functionality could redirect the browser to a different website. The problem has been fixed in version 2.6.1. Depending on how you have installed Products.PluggableAuthService, you should change the buildout version pin to `2.6.1` and re-run the buildout, or if you used `pip` simply do `pip install \"Products.PluggableAuthService>=2.6.1\".","published":"2021-03-08T21:15:16.807Z","modified":"2026-07-09T12:20:30.672404Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"products-pluggableauthservice","fixedVersion":"2.6.1"}],"fix":{"url":"https://github.com/zopefoundation/Products.PluggableAuthService/commit/7eead067898852ebd3e0f143bc51295928528dfa","label":"zopefoundation/Products.PluggableAuthService@7eead06"},"references":[{"type":"ADVISORY","url":"https://github.com/zopefoundation/Products.PluggableAuthService/security/advisories/GHSA-p44j-xrqg-4xrr"},{"type":"FIX","url":"https://github.com/zopefoundation/Products.PluggableAuthService/commit/7eead067898852ebd3e0f143bc51295928528dfa"},{"type":"PACKAGE","url":"https://pypi.org/project/Products.PluggableAuthService/"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/162911/Products.PluggableAuthService-2.6.0-Open-Redirect.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T12:20:30.672404Z"}}