CVE-2022-47500

CVE-2022-47500: Apache Helix: Open redirect

Vendor Apache Software Foundation
Product Apache Helix
Weakness CWE-601 · Open redirect
Published December 19, 2022
Last update April 17, 2025

CVSS base score

What the vulnerability does

Description

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache Helix all releases from 0.8.0 to 1.0.4. Solution: removed the the forward component since it was improper designed for UI embedding.  User please upgrade to 1.1.0 to fix this issue.

Key dates

Disclosure timeline

December 19, 2022 CVE published
April 17, 2025 Record updated