VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,767)

page 23 of 89
  • CVE-2022-46784MedFeb 23, 2023
    risk 0.40cvss 6.1epss 0.00

    SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection. (The issue was originally found in 5.5.1 GA.)

  • CVE-2022-38779MedFeb 22, 2023
    risk 0.40cvss 6.1epss 0.01

    An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.

  • CVE-2023-23860MedFeb 14, 2023
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a link, which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or…

  • CVE-2023-23853MedFeb 14, 2023
    risk 0.40cvss 6.1epss 0.00

    An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspecting user can be used to redirect a user to a malicious…

  • CVE-2023-22798MedFeb 9, 2023
    risk 0.40cvss 6.1epss 0.00

    Prior to commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0, https://github.com/brave/adblock-lists removed redirect interceptors on some websites like Facebook in which the redirect interceptor may have been there for security purposes. This could potentially cause open redirects…

  • CVE-2023-22418MedFeb 1, 2023
    risk 0.40cvss 6.1epss 0.00

    On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated…

  • CVE-2023-24445MedJan 26, 2023
    risk 0.40cvss 6.1epss 0.01

    Jenkins OpenID Plugin 2.4 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins.

  • CVE-2023-24044MedJan 22, 2023
    risk 0.40cvss 6.1epss 0.02

    A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request header. NOTE: the vendor's position is "the ability to use arbitrary domain names to access the panel is an intended…

  • CVE-2023-22298MedJan 17, 2023
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.

  • CVE-2023-0042MedJan 12, 2023
    risk 0.40cvss 6.1epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2. GitLab Pages allows redirection to arbitrary protocols.

  • CVE-2023-22958MedJan 11, 2023
    risk 0.40cvss 6.1epss 0.00

    The Syracom Secure Login plugin before 3.1.1.0 for Jira may allow spoofing of 2FA PIN validation via the plugins/servlet/twofactor/public/pinvalidation target parameter.

  • CVE-2022-3614MedJan 3, 2023
    risk 0.40cvss 6.1epss 0.00

    In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypass authentication checks and be redirected to the configured redirect url without any validation.

  • CVE-2022-38208MedDec 29, 2022
    risk 0.40cvss 6.1epss 0.00

    There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

  • CVE-2022-45413MedDec 22, 2022
    risk 0.40cvss 6.1epss 0.00

    Using the S.browser_fallback_url parameter parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be sent.*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects…

  • CVE-2022-36316MedDec 22, 2022
    risk 0.40cvss 6.1epss 0.00

    When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL had been subject to a redirect. This vulnerability affects Firefox < 103.

  • CVE-2022-34474MedDec 22, 2022
    risk 0.40cvss 6.1epss 0.00

    Even when an iframe was sandboxed with allow-top-navigation-by-user-activation, if it received a redirect header to an external protocol the browser would process the redirect and prompt the user as appropriate. This vulnerability affects Firefox < 102.

  • CVE-2022-29912MedDec 22, 2022
    risk 0.40cvss 6.1epss 0.01

    Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

  • CVE-2022-29910MedDec 22, 2022
    risk 0.40cvss 6.1epss 0.00

    When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.*Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 100.

  • CVE-2022-47500MedDec 19, 2022
    risk 0.40cvss 6.1epss 0.01

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache Helix all releases from 0.8.0 to 1.0.4. Solution: removed the the forward component since it was improper designed for UI…

  • CVE-2022-38662MedDec 19, 2022
    risk 0.40cvss 6.1epss 0.00

     In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.