VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,692)

page 84 of 85
  • CVE-2021-29651MedApr 2, 2021
    risk 0.00cvss 6.1epss 0.01

    Pomerium before 0.13.4 has an Open Redirect (issue 1 of 2).

  • CVE-2021-21354HigMar 8, 2021
    risk 0.00cvss 7.4epss 0.01

    Pollbot is open source software which "frees its human masters from the toilsome task of polling for the state of things during the Firefox release process." In Pollbot before version 1.4.4 there is an open redirection vulnerability in the path of…

  • CVE-2020-28724MedNov 18, 2020
    risk 0.00cvss 6.1epss 0.02

    Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.

  • CVE-2020-8559MedJul 22, 2020
    risk 0.00cvss 6.4epss 0.06

    The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.

  • CVE-2017-18891MedJun 19, 2020
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.

  • CVE-2020-6803MedFeb 28, 2020
    risk 0.00cvss 5.4epss 0.01

    An open redirect is present on the gateway's login page, which could cause a user to be redirected to a malicious site after logging in.

  • CVE-2019-19775MedDec 18, 2019
    risk 0.00cvss 6.1epss 0.01

    The image thumbnailing handler in Zulip Server versions 1.9.0 to before 2.0.8 allowed an open redirect that was visible to logged-in users.

  • CVE-2019-14857MedNov 26, 2019
    risk 0.00cvss 6.1epss 0.02

    A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with trailing slashes similar to CVE-2019-3877 in mod_auth_mellon.

  • CVE-2019-6009MedSep 12, 2019
    risk 0.00cvss 6.1epss 0.02

    Open redirect vulnerability in SHIRASAGI v1.7.0 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

  • CVE-2019-3877MedMar 27, 2019
    risk 0.00cvss 5.8epss 0.02

    A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as…

  • CVE-2019-9837MedMar 21, 2019
    risk 0.00cvss 6.1epss 0.01

    Doorkeeper::OpenidConnect (aka the OpenID Connect extension for Doorkeeper) 1.4.x and 1.5.x before 1.5.4 has an open redirect via the redirect_uri field in an OAuth authorization request (that results in an error response) with the 'openid' scope and a prompt=none value. This…

  • CVE-2018-11119MedMay 17, 2018
    risk 0.00cvss 6.1epss 0.01

    ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 redirects a logged-in user to a third-party site via the return_to_url parameter.

  • CVE-2015-5210Nov 2, 2015
    risk 0.00cvss epss 0.04

    Open redirect vulnerability in Apache Ambari before 2.1.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the targetURI parameter.

  • CVE-2015-5062Jun 24, 2015
    risk 0.00cvss epss 0.02

    Open redirect vulnerability in SilverStripe CMS & Framework 3.1.13 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the returnURL parameter to dev/build.

  • CVE-2015-3175Jun 1, 2015
    risk 0.00cvss epss 0.02

    Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an error page that links to a URL…

  • CVE-2015-0697Apr 15, 2015
    risk 0.00cvss epss 0.02

    Open redirect vulnerability in the login page in Cisco TC Software before 6.3-26 and 7.x before 7.3.0 on Cisco TelePresence Collaboration Desk and Room Endpoints devices allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified…

  • CVE-2015-1164Jan 21, 2015
    risk 0.00cvss epss 0.03

    Open redirect vulnerability in the serve-static plugin before 1.7.2 for Node.js, when mounted at the root, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the PATH_INFO to the default…

  • CVE-2013-7335Mar 12, 2014
    risk 0.00cvss epss 0.01

    Open redirect vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

  • CVE-2013-4195Mar 11, 2014
    risk 0.00cvss epss 0.01

    Multiple open redirect vulnerabilities in (1) marmoset_patch.py, (2) publish.py, and (3) principiaredirect.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via…

  • CVE-2013-6389Dec 7, 2013
    risk 0.00cvss epss 0.01

    Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.24 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.