Description
This issue occurs when handling HTTP 'Location:' redirect requests. The software fails to verify target protocols used in an automatic redirect request. An attacker running a malicious server could redirect a URI request and use a URI handler such as 'file://' to obtain files from a vulnerable computer.
Remediation
The web application should not permit redirects from http:// to file://.
References
Related Vulnerabilities
RubyGems Improper Input Validation Vulnerability (CVE-2018-1000077)
Magento Improper Input Validation Vulnerability (CVE-2021-28585)
Ruby on Rails Improper Input Validation Vulnerability (CVE-2011-3187)
ownCloud Improper Input Validation Vulnerability (CVE-2013-2044)
Plone CMS Improper Input Validation Vulnerability (CVE-2013-4199)