S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2019-3912 Scanner

CVE-2019-3912 scanner - Open Redirect vulnerability in Tenable LabKey Server Community Edition

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-3912
6.1
CVSS

An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticated remote attacker to redirect users to arbitrary web sites.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
LabKey Server Community Editionby Tenable
Versions before 18.3.0-61806.763
Updated Aug 21, 2026View on NVD →
Detail

Tenable LabKey Server Community Edition is a widely used open-source platform that allows users to manage and share biomedical data. It offers flexible data integration, compliance with industry standards, and secure data management. This platform is designed for laboratory data management, target discovery, and collaboration between research partners. 

However, this platform was recently found to have a major vulnerability identified as CVE-2019-3912. This vulnerability is an open redirect vulnerability, which allows an attacker to redirect a user to any external malicious website without their consent. An unauthenticated remote attacker can easily exploit this vulnerability by using the returnURL parameter in the platform’s __r1 URL, which is usually intended to redirect users back to the original page after a successful login. 

When exploited, this vulnerability can lead to various malicious activities such as phishing attacks, credential theft, and unauthorized access to sensitive data. An attacker can easily manipulate the redirected URL and craft a convincing phishing page that looks similar to the original site, tricking users into entering their login credentials or providing other sensitive information.

In conclusion, vulnerabilities like these can pose a severe threat to the security of any organization's digital assets. To be proactive in ensuring the security of your data, you need a reliable and comprehensive security solution. With the pro features of the s4e.io platform, you can easily and quickly learn about vulnerabilities in your digital assets, and take necessary actions to mitigate potential threats. This ensures that you always stay one step ahead of attackers.

 

REFERENCES

Solution Advice

To prevent this vulnerability from being exploited, several precautions can be taken, including: 

  • Avoid clicking on untrusted or suspicious links that might lead to external websites.
  • Always verify the URL of the link before clicking on them. Check for any unusual characters or domain names that seem out of place.
  • Monitor the system logs for any suspicious activities.
  • Install the latest security updates provided by Tenable LabKey Server Community Edition.
  • Restrict the user’s access privileges based on their roles and responsibilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-3912 scanner - Open Redirect vulnerability in Tenable LabKey Server Community Edition | S4E