CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Description
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-178
CVEs mapped to this weakness (1,692)
page 83 of 85| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-39258 | Hig | 0.00 | 8.1 | 0.01 | Sep 27, 2022 | mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger API template to spoof Authorize links. This could redirect a victim to an attacker controller place to steal Swagger authorization credentials or create a… | ||
| CVE-2021-28861 | Hig | 0.00 | 7.4 | 0.02 | Aug 23, 2022 | Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html… | ||
| CVE-2021-3639 | Med | 0.00 | 6.1 | 0.01 | Aug 22, 2022 | A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious… | ||
| CVE-2022-23078 | 0.00 | — | 0.01 | Jun 22, 2022 | In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page. | |||
| CVE-2022-31040 | Hig | 0.00 | 7.1 | 0.01 | Jun 13, 2022 | Open Forms is an application for creating and publishing smart forms. Prior to versions 1.0.9 and 1.1.1, the cookie consent page in Open Forms contains an open redirect by injecting a `referer` querystring parameter and failing to validate the value. A malicious actor is able to… | ||
| CVE-2022-29170 | Med | 0.00 | 6.6 | 0.01 | May 20, 2022 | Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerability present starting with… | ||
| CVE-2022-1774 | Med | 0.00 | 6.1 | 0.01 | May 18, 2022 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7. | ||
| CVE-2022-24887 | Med | 0.00 | 4.3 | 0.01 | Apr 27, 2022 | Nextcloud Talk is a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. Prior to versions 11.3.4, 12.2.2, and 13.0.0, when sharing a Deck card in conversation, the metaData can be manipulated so users can be tricked into opening arbitrary URLs.… | ||
| CVE-2022-0645 | Med | 0.00 | 6.1 | 0.01 | Apr 19, 2022 | Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to 1.34.1. | ||
| CVE-2022-24776 | Med | 0.00 | 6.1 | 0.01 | Mar 24, 2022 | Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder contains an open redirect vulnerability when using database authentication login page on versions below 3.4.5. This issue is fixed in version 3.4.5. There are… | ||
| CVE-2021-41180 | Med | 0.00 | 4.7 | 0.01 | Mar 8, 2022 | Nextcloud talk is a self hosting messaging service. In versions prior 12.1.2 an attacker is able to control the link of a geolocation preview in the Nextcloud Talk application due to a lack of validation on the link. This could result in an open-redirect, but required user… | ||
| CVE-2022-25196 | Med | 0.00 | 5.4 | 0.01 | Feb 15, 2022 | Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication process starts, allowing attackers with access to Jenkins to craft a URL that will redirect users to an attacker-specified URL after… | ||
| CVE-2021-3829 | Med | 0.00 | 6.1 | 0.01 | Dec 10, 2021 | openwhyd is vulnerable to URL Redirection to Untrusted Site | ||
| CVE-2021-43777 | Med | 0.00 | 6.8 | 0.00 | Nov 24, 2021 | Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly uses the `state` parameter to pass the next URL to redirect the user to after login. The `state` parameter should be used for a… | ||
| CVE-2021-41733 | Med | 0.00 | 6.1 | 0.01 | Nov 8, 2021 | Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them. | ||
| CVE-2021-23435 | Hig | 0.00 | 7.6 | 0.01 | Sep 12, 2021 | This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value of session[:return_to]. If the value used for return_to contains multiple leading slashes (/////example.com) the user ends up being redirected to the external… | ||
| CVE-2021-39191 | Med | 0.00 | 4.7 | 0.02 | Sep 3, 2021 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9.4, the 3rd-party init SSO functionality of… | ||
| CVE-2021-32786 | Med | 0.00 | 4.7 | 0.02 | Jul 22, 2021 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9, `oidc_validate_redirect_url()` does not parse URLs… | ||
| CVE-2021-35206 | Med | 0.00 | 6.1 | 0.01 | Jun 22, 2021 | Gitpod before 0.6.0 allows unvalidated redirects. | ||
| CVE-2021-29652 | Med | 0.00 | 6.1 | 0.01 | Apr 2, 2021 | Pomerium from version 0.10.0-0.13.3 has an Open Redirect in the user sign-in/out process |
- risk 0.00cvss 8.1epss 0.01
mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger API template to spoof Authorize links. This could redirect a victim to an attacker controller place to steal Swagger authorization credentials or create a…
- risk 0.00cvss 7.4epss 0.02
Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html…
- risk 0.00cvss 6.1epss 0.01
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious…
- CVE-2022-23078Jun 22, 2022risk 0.00cvss —epss 0.01
In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page.
- risk 0.00cvss 7.1epss 0.01
Open Forms is an application for creating and publishing smart forms. Prior to versions 1.0.9 and 1.1.1, the cookie consent page in Open Forms contains an open redirect by injecting a `referer` querystring parameter and failing to validate the value. A malicious actor is able to…
- risk 0.00cvss 6.6epss 0.01
Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerability present starting with…
- risk 0.00cvss 6.1epss 0.01
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7.
- risk 0.00cvss 4.3epss 0.01
Nextcloud Talk is a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. Prior to versions 11.3.4, 12.2.2, and 13.0.0, when sharing a Deck card in conversation, the metaData can be manipulated so users can be tricked into opening arbitrary URLs.…
- risk 0.00cvss 6.1epss 0.01
Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to 1.34.1.
- risk 0.00cvss 6.1epss 0.01
Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder contains an open redirect vulnerability when using database authentication login page on versions below 3.4.5. This issue is fixed in version 3.4.5. There are…
- risk 0.00cvss 4.7epss 0.01
Nextcloud talk is a self hosting messaging service. In versions prior 12.1.2 an attacker is able to control the link of a geolocation preview in the Nextcloud Talk application due to a lack of validation on the link. This could result in an open-redirect, but required user…
- risk 0.00cvss 5.4epss 0.01
Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication process starts, allowing attackers with access to Jenkins to craft a URL that will redirect users to an attacker-specified URL after…
- risk 0.00cvss 6.1epss 0.01
openwhyd is vulnerable to URL Redirection to Untrusted Site
- risk 0.00cvss 6.8epss 0.00
Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly uses the `state` parameter to pass the next URL to redirect the user to after login. The `state` parameter should be used for a…
- risk 0.00cvss 6.1epss 0.01
Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them.
- risk 0.00cvss 7.6epss 0.01
This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value of session[:return_to]. If the value used for return_to contains multiple leading slashes (/////example.com) the user ends up being redirected to the external…
- risk 0.00cvss 4.7epss 0.02
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9.4, the 3rd-party init SSO functionality of…
- risk 0.00cvss 4.7epss 0.02
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9, `oidc_validate_redirect_url()` does not parse URLs…
- risk 0.00cvss 6.1epss 0.01
Gitpod before 0.6.0 allows unvalidated redirects.
- risk 0.00cvss 6.1epss 0.01
Pomerium from version 0.10.0-0.13.3 has an Open Redirect in the user sign-in/out process