{"id":"CVE-2017-7266","details":"Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the \"next\" parameter which then redirects to any domain irrespective of the Host header.","aliases":["GHSA-j6jq-3q8p-xgg6","PYSEC-2026-919"],"modified":"2026-07-07T11:56:36.756389237Z","published":"2017-03-26T05:59:00.273Z","database_specific":{},"references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/97088"},{"type":"ADVISORY","url":"https://github.com/Netflix/security_monkey/pull/482"},{"type":"ADVISORY","url":"https://github.com/Netflix/security_monkey/releases/tag/v0.8.0"},{"type":"FIX","url":"https://github.com/Netflix/security_monkey/commit/3b4da13efabb05970c80f464a50d3c1c12262466"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}