CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Description
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-178
CVEs mapped to this weakness (1,767)
page 87 of 89| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29170 | Med | 0.00 | 6.6 | 0.01 | May 20, 2022 | Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerability present starting with… | ||
| CVE-2022-1774 | Med | 0.00 | 6.1 | 0.01 | May 18, 2022 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7. | ||
| CVE-2022-24887 | Med | 0.00 | 4.3 | 0.01 | Apr 27, 2022 | Nextcloud Talk is a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. Prior to versions 11.3.4, 12.2.2, and 13.0.0, when sharing a Deck card in conversation, the metaData can be manipulated so users can be tricked into opening arbitrary URLs.… | ||
| CVE-2022-0645 | Med | 0.00 | 6.1 | 0.01 | Apr 19, 2022 | Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to 1.34.1. | ||
| CVE-2022-24776 | Med | 0.00 | 6.1 | 0.01 | Mar 24, 2022 | Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder contains an open redirect vulnerability when using database authentication login page on versions below 3.4.5. This issue is fixed in version 3.4.5. There are… | ||
| CVE-2021-41180 | Med | 0.00 | 4.7 | 0.01 | Mar 8, 2022 | Nextcloud talk is a self hosting messaging service. In versions prior 12.1.2 an attacker is able to control the link of a geolocation preview in the Nextcloud Talk application due to a lack of validation on the link. This could result in an open-redirect, but required user… | ||
| CVE-2022-25196 | Med | 0.00 | 5.4 | 0.01 | Feb 15, 2022 | Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication process starts, allowing attackers with access to Jenkins to craft a URL that will redirect users to an attacker-specified URL after… | ||
| CVE-2021-3829 | Med | 0.00 | 6.1 | 0.01 | Dec 10, 2021 | openwhyd is vulnerable to URL Redirection to Untrusted Site | ||
| CVE-2021-43777 | Med | 0.00 | 6.8 | 0.00 | Nov 24, 2021 | Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly uses the `state` parameter to pass the next URL to redirect the user to after login. The `state` parameter should be used for a… | ||
| CVE-2021-41733 | Med | 0.00 | 6.1 | 0.01 | Nov 8, 2021 | Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them. | ||
| CVE-2021-23435 | Hig | 0.00 | 7.6 | 0.01 | Sep 12, 2021 | This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value of session[:return_to]. If the value used for return_to contains multiple leading slashes (/////example.com) the user ends up being redirected to the external… | ||
| CVE-2021-39191 | Med | 0.00 | 4.7 | 0.02 | Sep 3, 2021 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9.4, the 3rd-party init SSO functionality of… | ||
| CVE-2021-32786 | Med | 0.00 | 4.7 | 0.02 | Jul 22, 2021 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9, `oidc_validate_redirect_url()` does not parse URLs… | ||
| CVE-2021-35206 | Med | 0.00 | 6.1 | 0.01 | Jun 22, 2021 | Gitpod before 0.6.0 allows unvalidated redirects. | ||
| CVE-2021-29652 | Med | 0.00 | 6.1 | 0.01 | Apr 2, 2021 | Pomerium from version 0.10.0-0.13.3 has an Open Redirect in the user sign-in/out process | ||
| CVE-2021-29651 | Med | 0.00 | 6.1 | 0.01 | Apr 2, 2021 | Pomerium before 0.13.4 has an Open Redirect (issue 1 of 2). | ||
| CVE-2021-21354 | Hig | 0.00 | 7.4 | 0.01 | Mar 8, 2021 | Pollbot is open source software which "frees its human masters from the toilsome task of polling for the state of things during the Firefox release process." In Pollbot before version 1.4.4 there is an open redirection vulnerability in the path of… | ||
| CVE-2020-28724 | Med | 0.00 | 6.1 | 0.02 | Nov 18, 2020 | Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL. | ||
| CVE-2020-8559 | Med | 0.00 | 6.4 | 0.06 | Jul 22, 2020 | The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise. | ||
| CVE-2017-18891 | Med | 0.00 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link. |
- risk 0.00cvss 6.6epss 0.01
Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerability present starting with…
- risk 0.00cvss 6.1epss 0.01
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7.
- risk 0.00cvss 4.3epss 0.01
Nextcloud Talk is a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. Prior to versions 11.3.4, 12.2.2, and 13.0.0, when sharing a Deck card in conversation, the metaData can be manipulated so users can be tricked into opening arbitrary URLs.…
- risk 0.00cvss 6.1epss 0.01
Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to 1.34.1.
- risk 0.00cvss 6.1epss 0.01
Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder contains an open redirect vulnerability when using database authentication login page on versions below 3.4.5. This issue is fixed in version 3.4.5. There are…
- risk 0.00cvss 4.7epss 0.01
Nextcloud talk is a self hosting messaging service. In versions prior 12.1.2 an attacker is able to control the link of a geolocation preview in the Nextcloud Talk application due to a lack of validation on the link. This could result in an open-redirect, but required user…
- risk 0.00cvss 5.4epss 0.01
Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication process starts, allowing attackers with access to Jenkins to craft a URL that will redirect users to an attacker-specified URL after…
- risk 0.00cvss 6.1epss 0.01
openwhyd is vulnerable to URL Redirection to Untrusted Site
- risk 0.00cvss 6.8epss 0.00
Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly uses the `state` parameter to pass the next URL to redirect the user to after login. The `state` parameter should be used for a…
- risk 0.00cvss 6.1epss 0.01
Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them.
- risk 0.00cvss 7.6epss 0.01
This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value of session[:return_to]. If the value used for return_to contains multiple leading slashes (/////example.com) the user ends up being redirected to the external…
- risk 0.00cvss 4.7epss 0.02
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9.4, the 3rd-party init SSO functionality of…
- risk 0.00cvss 4.7epss 0.02
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9, `oidc_validate_redirect_url()` does not parse URLs…
- risk 0.00cvss 6.1epss 0.01
Gitpod before 0.6.0 allows unvalidated redirects.
- risk 0.00cvss 6.1epss 0.01
Pomerium from version 0.10.0-0.13.3 has an Open Redirect in the user sign-in/out process
- risk 0.00cvss 6.1epss 0.01
Pomerium before 0.13.4 has an Open Redirect (issue 1 of 2).
- risk 0.00cvss 7.4epss 0.01
Pollbot is open source software which "frees its human masters from the toilsome task of polling for the state of things during the Firefox release process." In Pollbot before version 1.4.4 there is an open redirection vulnerability in the path of…
- risk 0.00cvss 6.1epss 0.02
Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.
- risk 0.00cvss 6.4epss 0.06
The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.
- risk 0.00cvss 6.1epss 0.01
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.