graylog-labs / graylog2-web-interface

[DEPRECATED]
https://www.graylog.org/
611 stars 174 forks source link

Only redirect to relative URLs on login #1729

Closed edmundoa closed 8 years ago

edmundoa commented 8 years ago

Do not redirect to absolute URLs after login, as this could allow someone to send a manipulated URL pointing to any external (and potentially dangerous) site.