CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,633 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 14 of 33
- CVE-2022-24776MEDIUMCVSS 6.1EG 6.12022-03-24
Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder contains an open redirect vulnerability when using database authentication login page on versions below 3.4.5. This issue i…
- CVE-2022-24794HIGHCVSS 7.5EG 7.52022-03-31
Express OpenID Connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect. Users of the `requiresAuth` middleware, either directly or through the default `authRequired` option, are vulnerable to an O…
- CVE-2022-24858MEDIUMCVSS 6.1EG 6.12022-04-19
next-auth v3 users before version 3.29.2 are impacted. next-auth version 4 users before version 4.3.2 are also impacted. Upgrading to 3.29.2 or 4.3.2 will patch this vulnerability. If you are not able to upgrade for any reason, you can add…
- CVE-2022-24887MEDIUMCVSS 4.3EG 4.32022-04-27
Nextcloud Talk is a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. Prior to versions 11.3.4, 12.2.2, and 13.0.0, when sharing a Deck card in conversation, the metaData can be manipulated so users can b…
- CVE-2022-24969MEDIUMCVSS 6.1EG 6.12022-06-09
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.
- CVE-2022-25196MEDIUMCVSS 5.4EG 5.42022-02-15
Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication process starts, allowing attackers with access to Jenkins to craft a URL that will redirect u…
- CVE-2022-25295MEDIUMCVSS 5.4EG 5.42022-09-11
This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The application uses url.Parse(r.FormValue("next")) to extract path and eventually redirect user to a re…
- CVE-2022-25799MEDIUMCVSS 6.1EG 6.12022-08-16
An open redirect vulnerability exists in CERT/CC VINCE software prior to 1.50.0. An attacker could send a link that has a specially crafted URL and convince the user to click the link. When an authenticated user clicks the link, the authen…
- CVE-2022-25803MEDIUMCVSS 6.1EG 6.12022-07-14
Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search.
- CVE-2022-26156MEDIUMCVSS 6.1EG 6.12022-02-28
An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. Injection of a malicious payload within the RelayState= parameter of the HTTP request body results in the hijacking of the form action. Form-action…
- CVE-2022-26158MEDIUMCVSS 6.1EG 6.12022-02-28
An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. It accepts and reflects arbitrary domains supplied via a client-controlled Host header. Injection of a malicious URL in the Host: header of the HTT…
- CVE-2022-26326MEDIUMCVSS 4.0EG 6.12022-05-02
Potential open redirection vulnerability when URL is crafted in specific format in NetIQ Access Manager prior to 5.0.2
- CVE-2022-26950MEDIUMCVSS 5.4EG 6.12022-03-30
Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal …
- CVE-2022-26954MEDIUMCVSS 6.1EG 6.12022-10-20
Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing attacks by redirecting users to attacker-controlled web sites via the returnUrl parameter, processed by the (1) ChangePass…
- CVE-2022-27090MEDIUMCVSS 5.4EG 5.42022-03-21
Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter.
- CVE-2022-27109MEDIUMCVSS 5.4EG 5.42022-04-06
OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability.
- CVE-2022-27110MEDIUMCVSS 5.4EG 5.42022-04-06
OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.
- CVE-2022-27256MEDIUMCVSS 6.1EG 6.12022-04-13
A PHP Local File inclusion vulnerability in the Redbasic theme for Hubzilla before version 7.2 allows remote attackers to include arbitrary php files via the schema parameter.
- CVE-2022-27461MEDIUMCVSS 6.1EG 6.12022-05-04
In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce page by clicking on a crafted link.
- CVE-2022-27463MEDIUMCVSS 6.1EG 6.12022-04-05
Open redirect vulnerability in objects/login.json.php in WWBN AVideo through 11.6, allows attackers to arbitrarily redirect users from a crafted url to the login page.
- CVE-2022-27509MEDIUMCVSS 6.1EG 6.12022-07-28
Unauthenticated redirection to a malicious website
- CVE-2022-27547HIGHCVSS 6.1EG 7.42022-08-29
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.
- CVE-2022-27861MEDIUMCVSS 4.7EG 4.72023-08-10
Unauth. Open Redirect vulnerability in Arscode Ninja Popups plugin <= 4.7.5 versions.
- CVE-2022-28215MEDIUMCVSS 4.7EG 4.72022-04-12
SAP NetWeaver ABAP Server and ABAP Platform - versions 740, 750, 787, allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked to disclose person…
- CVE-2022-2837MEDIUMCVSS 6.1EG 6.12023-03-03
A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.
- CVE-2022-28755CRITICALCVSS 9.6EG 9.62022-08-11
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect t…
- CVE-2022-28763CRITICALCVSS 8.8EG 9.62022-10-31
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to…
- CVE-2022-28923MEDIUMCVSS 6.1EG 6.12023-02-06
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.
- CVE-2022-28977MEDIUMCVSS 6.1EG 6.12022-09-22
HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack 17 through 25, 7.2 fix pack 5 through 14, and 7.3 before service pack 3 can be circumvented by using multiple forward …
- CVE-2022-29170MEDIUMCVSS 6.6EG 6.62022-05-20
Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The…
- CVE-2022-29214MEDIUMCVSS 6.1EG 6.12022-05-21
NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. Prior to versions 3.29.3 and 4.3.3, an open redirect vulnerability is present when the developer is implementing an OAuth 1 provider. Versions 3.29…
- CVE-2022-29272MEDIUMCVSS 6.1EG 6.12022-06-29
In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
- CVE-2022-29718MEDIUMCVSS 6.1EG 6.12022-06-02
Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
- CVE-2022-29910MEDIUMCVSS 6.1EG 6.12022-12-22
When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.<br>*Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Fi…
- CVE-2022-29912MEDIUMCVSS 6.1EG 6.12022-12-22
Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
- CVE-2022-30562MEDIUMCVSS 4.7EG 4.72022-06-28
If the user enables the https function on the device, an attacker can modify the user’s request data packet through a man-in-the-middle attack ,Injection of a malicious URL in the Host: header of the HTTP Request results in a 302 redirec…
- CVE-2022-30706MEDIUMCVSS 6.1EG 6.12022-07-26
Open redirect vulnerability in Booked versions prior to 3.3 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.
- CVE-2022-30992MEDIUMCVSS 6.1EG 6.12022-05-18
Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240
- CVE-2022-31040HIGHCVSS 7.1EG 7.12022-06-13
Open Forms is an application for creating and publishing smart forms. Prior to versions 1.0.9 and 1.1.1, the cookie consent page in Open Forms contains an open redirect by injecting a `referer` querystring parameter and failing to validate…
- CVE-2022-31151LOWCVSS 3.7EG 3.72022-07-21
Authorization headers are cleared on cross-origin redirect. However, cookie headers which are sensitive headers and are official headers found in the spec, remain uncleared. There are active users using cookie headers in undici. This may l…
- CVE-2022-31193HIGHCVSS 7.1EG 7.12022-08-01
DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI controlled vocabulary servlet is vulnerable to an open redirect attack, where …
- CVE-2022-3145MEDIUMCVSS 4.7EG 4.72023-01-12
An open redirect vulnerability exists in Okta OIDC Middleware prior to version 5.0.0 allowing an attacker to redirect a user to an arbitrary URL.
- CVE-2022-31657CRITICALCVSS 9.8EG 9.82022-08-05
VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect an authenticated user to an arbitrary domain.
- CVE-2022-31735MEDIUMCVSS 6.1EG 6.12022-09-15
OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601). When accessing an affected server through some specially crafted URL, the user may be redirected to an arbitrary webs…
- CVE-2022-32444MEDIUMCVSS 6.1EG 6.12022-06-17
An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser to be redirected to another site via /loginsave.php.
- CVE-2022-3280MEDIUMCVSS 3.5EG 6.12022-11-09
An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content.
- CVE-2022-33146MEDIUMCVSS 6.1EG 6.12022-06-27
Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.
- CVE-2022-33712MEDIUMCVSS 5.3EG 5.32022-07-12
Intent redirection vulnerability using implict intent in Camera prior to versions 12.0.01.64 ,12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19 in Android S(12) allows attacker to get sensitive information.
- CVE-2022-3381MEDIUMCVSS 4.3EG 6.12023-03-09
An issue has been discovered in GitLab affecting all versions starting from 10.0 to 15.7.8, 15.8 prior to 15.8.4 and 15.9 prior to 15.9.2. A crafted URL could be used to redirect users to arbitrary sites
- CVE-2022-3438MEDIUMCVSS 6.1EG 6.12022-10-10
Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →