CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,776 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 15 of 36
- CVE-2023-26494MEDIUMCVSS 6.1EG 6.12023-04-24
lorawan-stack is an open source LoRaWAN network server. Prior to version 3.24.1, an open redirect exists on the login page of the lorawan stack server, allowing an attacker to supply a user controlled redirect upon sign in. This issue may …
- CVE-2023-24935MEDIUMCVSS 6.1EG 6.12023-04-11
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2023-28069MEDIUMCVSS 6.1EG 6.12023-04-05
Dell Streaming Data Platform prior to 1.4 contains Open Redirect vulnerability. A remote unauthenticated attacker can phish the legitimate user to redirect to malicious website leading to information disclosure and launch of phishing atta…
- CVE-2022-2237MEDIUMCVSS 6.1EG 6.12023-03-27
A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso function.
- CVE-2023-0876MEDIUMCVSS 6.1EG 6.12023-03-20
The WP Meta SEO WordPress plugin before 4.5.3 does not authorize several ajax actions, allowing low-privilege users to make updates to certain data and leading to an arbitrary redirect vulnerability.
- CVE-2023-24735MEDIUMCVSS 6.1EG 6.12023-03-06
PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerability allows attackers to redirect victim users to an external domain via a crafted URL.
- CVE-2023-22432MEDIUMCVSS 6.1EG 6.12023-03-06
Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirected to an arbitrary website by accessing a specially crafted URL. As a result, the user may become a victim of a phishi…
- CVE-2022-2837MEDIUMCVSS 6.1EG 6.12023-03-03
A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.
- CVE-2022-46784MEDIUMCVSS 6.1EG 6.12023-02-23
SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection. (The issue was originally found in 5.5.1 GA.)
- CVE-2022-38779MEDIUMCVSS 6.1EG 6.12023-02-22
An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.
- CVE-2022-0637MEDIUMCVSS 6.1EG 6.12023-02-16
open redirect in pollbot (pollbot.services.mozilla.com) in versions before 1.4.6
- CVE-2023-23860MEDIUMCVSS 6.1EG 6.12023-02-14
SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a link, which when clicked by an unsuspecting user can be used to redirect a user to …
- CVE-2023-23853MEDIUMCVSS 6.1EG 6.12023-02-14
An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspecting user can be u…
- CVE-2023-22798MEDIUMCVSS 6.1EG 6.12023-02-09
Prior to commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0, https://github.com/brave/adblock-lists removed redirect interceptors on some websites like Facebook in which the redirect interceptor may have been there for security purposes. This…
- CVE-2023-22797MEDIUMCVSS 6.1EG 6.12023-02-09
An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling redirect_to with untrusted user input. In prior versions the developer was fully responsible for only providing trusted in…
- CVE-2022-28923MEDIUMCVSS 6.1EG 6.12023-02-06
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.
- CVE-2023-22418MEDIUMCVSS 6.1EG 6.12023-02-01
On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This v…
- CVE-2022-4496MEDIUMCVSS 6.1EG 6.12023-01-30
The SAML SSO Standard WordPress plugin version 16.0.0 before 16.0.8, SAML SSO Premium WordPress plugin version 12.0.0 before 12.1.0 and SAML SSO Premium Multisite WordPress plugin version 20.0.0 before 20.0.7 does not validate that the red…
- CVE-2023-24445MEDIUMCVSS 6.1EG 6.12023-01-26
Jenkins OpenID Plugin 2.4 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins.
- CVE-2023-24044MEDIUMCVSS 6.1EG 6.12023-01-22
A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request header. NOTE: the vendor's position is "the ability to use arbitrary domain names…
- CVE-2023-22298MEDIUMCVSS 6.1EG 6.12023-01-17
Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.
- CVE-2023-0042MEDIUMCVSS 6.1EG 6.12023-01-12
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2. GitLab Pages allows redirection to arbitrary protocols.
- CVE-2023-22958MEDIUMCVSS 6.1EG 6.12023-01-11
The Syracom Secure Login plugin before 3.1.1.0 for Jira may allow spoofing of 2FA PIN validation via the plugins/servlet/twofactor/public/pinvalidation target parameter.
- CVE-2022-3614MEDIUMCVSS 6.1EG 6.12023-01-03
In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypass authentication checks and be redirected to the configured redirect url without any validation.
- CVE-2022-38208MEDIUMCVSS 6.1EG 6.12022-12-29
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
- CVE-2022-4720MEDIUMCVSS 6.1EG 6.12022-12-27
Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.5.
- CVE-2022-45413MEDIUMCVSS 6.1EG 6.12022-12-22
Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be sent.<br>*This issue only affects Firefox for Android. Other operating systems are not af…
- CVE-2022-36316MEDIUMCVSS 6.1EG 6.12022-12-22
When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL had been subject to a redirect. This vulnerability affects Firefox < 103.
- CVE-2022-34474MEDIUMCVSS 6.1EG 6.12022-12-22
Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an external protocol the browser would process the redirect and prompt the user as appropriate. This vulnerabi…
- CVE-2022-29912MEDIUMCVSS 6.1EG 6.12022-12-22
Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
- CVE-2022-29910MEDIUMCVSS 6.1EG 6.12022-12-22
When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.<br>*Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Fi…
- CVE-2022-4644MEDIUMCVSS 6.1EG 6.12022-12-22
Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.4.
- CVE-2022-47500MEDIUMCVSS 6.1EG 6.12022-12-19
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache Helix all releases from 0.8.0 to 1.0.4. Solution: removed the the forward component sinc…
- CVE-2022-38662MEDIUMCVSS 6.1EG 6.12022-12-19
In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.
- CVE-2022-46288MEDIUMCVSS 6.1EG 6.12022-12-19
Open redirect vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted …
- CVE-2022-41275MEDIUMCVSS 6.1EG 6.12022-12-13
In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in user, can be redirected to a malicious page that could read or modify sensitive informat…
- CVE-2022-37927MEDIUMCVSS 6.1EG 6.12022-12-12
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Hewlett Packard Enterprise HPE OneView Global Dashboard (OVGD).
- CVE-2022-46683MEDIUMCVSS 6.1EG 6.12022-12-12
Jenkins Google Login Plugin 1.4 through 1.6 (both inclusive) improperly determines that a redirect URL after login is legitimately pointing to Jenkins.
- CVE-2022-45917MEDIUMCVSS 6.1EG 6.12022-12-07
ILIAS before 7.16 has an Open Redirect.
- CVE-2022-43479MEDIUMCVSS 6.1EG 6.12022-12-05
Open redirect vulnerability in SHIRASAGI v1.14.4 to v1.15.0 allows a remote unauthenticated attacker to redirect users to an arbitrary web site and conduct a phishing attack.
- CVE-2021-22141MEDIUMCVSS 6.1EG 6.12022-11-18
An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in Kibana redirecting the user to an arbitrary website.
- CVE-2022-38201MEDIUMCVSS 6.1EG 6.12022-11-15
An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticated attacker can potentially induce an unsuspecting authenticated user to access an an attac…
- CVE-2022-41260MEDIUMCVSS 6.1EG 6.12022-11-08
SAP Financial Consolidation - version 1010, does not sufficiently encode user-controlled input which may allow an unauthenticated attacker to inject a web script via a GET request. On successful exploitation, an attacker can view or modify…
- CVE-2022-41207MEDIUMCVSS 6.1EG 6.12022-11-08
SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting victim, it will use an unsensitized parameter to redirect the victim to a malicious site of the attacker's choosing whi…
- CVE-2022-43985MEDIUMCVSS 6.1EG 6.12022-11-02
In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint.
- CVE-2022-39021MEDIUMCVSS 6.1EG 6.12022-10-31
U-Office Force login function has an Open Redirect vulnerability. An unauthenticated remote attacker can exploit this vulnerability to redirect user to arbitrary website.
- CVE-2022-38197MEDIUMCVSS 6.1EG 6.12022-10-25
Esri ArcGIS Server versions 10.9.1 and below have an unvalidated redirect issue that may allow a remote, unauthenticated attacker to phish a user into accessing an attacker controlled website via a crafted query parameter.
- CVE-2022-26954MEDIUMCVSS 6.1EG 6.12022-10-20
Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing attacks by redirecting users to attacker-controlled web sites via the returnUrl parameter, processed by the (1) ChangePass…
- CVE-2022-3438MEDIUMCVSS 6.1EG 6.12022-10-10
Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.
- CVE-2022-28977MEDIUMCVSS 6.1EG 6.12022-09-22
HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack 17 through 25, 7.2 fix pack 5 through 14, and 7.3 before service pack 3 can be circumvented by using multiple forward …
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →