CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Description
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-178
CVEs mapped to this weakness (1,767)
page 56 of 89| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-32478 | Med | 0.33 | 6.1 | 0.01 | Mar 11, 2022 | The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected. | ||
| CVE-2022-0697 | Med | 0.33 | 6.1 | 0.01 | Mar 6, 2022 | Open Redirect in GitHub repository archivy/archivy prior to 1.7.0. | ||
| CVE-2022-0868 | Med | 0.33 | 6.1 | 0.01 | Mar 6, 2022 | Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10. | ||
| CVE-2022-0869 | Med | 0.33 | 6.1 | 0.03 | Mar 6, 2022 | Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3. | ||
| CVE-2022-0692 | Med | 0.33 | 6.1 | 0.03 | Feb 21, 2022 | Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1. | ||
| CVE-2022-0597 | Med | 0.33 | 6.1 | 0.03 | Feb 15, 2022 | Open Redirect in Packagist microweber/microweber prior to 1.2.11. | ||
| CVE-2021-25033 | Med | 0.33 | 6.1 | 0.02 | Feb 14, 2022 | The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue | ||
| CVE-2022-0560 | Med | 0.33 | 6.1 | 0.01 | Feb 11, 2022 | Open Redirect in Packagist microweber/microweber prior to 1.2.11. | ||
| CVE-2021-45328 | Med | 0.33 | 6.1 | 0.01 | Feb 8, 2022 | Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs. | ||
| CVE-2022-0235 | Med | 0.33 | 6.1 | 0.02 | Jan 16, 2022 | node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor | ||
| CVE-2021-44528 | Med | 0.33 | 6.1 | 0.04 | Jan 10, 2022 | A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. | ||
| CVE-2022-0122 | Med | 0.33 | 6.1 | 0.01 | Jan 6, 2022 | forge is vulnerable to URL Redirection to Untrusted Site | ||
| CVE-2021-4000 | Med | 0.33 | 6.1 | 0.01 | Dec 3, 2021 | showdoc is vulnerable to URL Redirection to Untrusted Site | ||
| CVE-2021-3989 | Med | 0.33 | 6.1 | 0.01 | Dec 1, 2021 | showdoc is vulnerable to URL Redirection to Untrusted Site | ||
| CVE-2021-3647 | Med | 0.33 | 6.1 | 0.01 | Jul 16, 2021 | URI.js is vulnerable to URL Redirection to Untrusted Site | ||
| CVE-2021-21673 | Med | 0.33 | 6.1 | 0.02 | Jun 30, 2021 | Jenkins CAS Plugin 1.6.0 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks. | ||
| CVE-2021-32645 | Med | 0.33 | 6.1 | 0.01 | May 27, 2021 | Tenancy multi-tenant is an open source multi-domain controller for the Laravel web framework. In some situations, it is possible to have open redirects where users can be redirected from your site to any other site using a specially crafted URL. This is only the case for… | ||
| CVE-2020-36365 | Med | 0.33 | 6.1 | 0.03 | May 19, 2021 | Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskController.Edit open redirect. | ||
| CVE-2020-35678 | Med | 0.33 | 6.1 | 0.01 | Dec 27, 2020 | Autobahn|Python before 20.12.3 allows redirect header injection. | ||
| CVE-2020-26275 | Med | 0.33 | 6.1 | 0.01 | Dec 21, 2020 | The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. In Jupyter Server before version 1.1.1, an open redirect vulnerability could cause the jupyter server to redirect… |
- risk 0.33cvss 6.1epss 0.01
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.
- risk 0.33cvss 6.1epss 0.01
Open Redirect in GitHub repository archivy/archivy prior to 1.7.0.
- risk 0.33cvss 6.1epss 0.01
Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.
- risk 0.33cvss 6.1epss 0.03
Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3.
- risk 0.33cvss 6.1epss 0.03
Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.
- risk 0.33cvss 6.1epss 0.03
Open Redirect in Packagist microweber/microweber prior to 1.2.11.
- risk 0.33cvss 6.1epss 0.02
The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue
- risk 0.33cvss 6.1epss 0.01
Open Redirect in Packagist microweber/microweber prior to 1.2.11.
- risk 0.33cvss 6.1epss 0.01
Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.
- risk 0.33cvss 6.1epss 0.02
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
- risk 0.33cvss 6.1epss 0.04
A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
- risk 0.33cvss 6.1epss 0.01
forge is vulnerable to URL Redirection to Untrusted Site
- risk 0.33cvss 6.1epss 0.01
showdoc is vulnerable to URL Redirection to Untrusted Site
- risk 0.33cvss 6.1epss 0.01
showdoc is vulnerable to URL Redirection to Untrusted Site
- risk 0.33cvss 6.1epss 0.01
URI.js is vulnerable to URL Redirection to Untrusted Site
- risk 0.33cvss 6.1epss 0.02
Jenkins CAS Plugin 1.6.0 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
- risk 0.33cvss 6.1epss 0.01
Tenancy multi-tenant is an open source multi-domain controller for the Laravel web framework. In some situations, it is possible to have open redirects where users can be redirected from your site to any other site using a specially crafted URL. This is only the case for…
- risk 0.33cvss 6.1epss 0.03
Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskController.Edit open redirect.
- risk 0.33cvss 6.1epss 0.01
Autobahn|Python before 20.12.3 allows redirect header injection.
- risk 0.33cvss 6.1epss 0.01
The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. In Jupyter Server before version 1.1.1, an open redirect vulnerability could cause the jupyter server to redirect…