← Back
CWE-601

1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low

URL Redirection to Untrusted Site ('Open Redirect')

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.

JSON object

Loading...

CVEs (1,576)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
1Keycloak
Nov 21, 2024
Dec 15, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Jun 17, 2026
Dec 11, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in th...Show more
MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.Show less
1Microsoft
2Visual Studio 2019
Visual Studio Live Share
Jun 17, 2026
Dec 10, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the session host, aka 'Visual Studio Live Share Spoofing Vulnerabi...Show more
A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the session host, aka 'Visual Studio Live Share Spoofing Vulnerability'.Show less
1Jetbrains
1Ktor
Jun 17, 2026
Dec 10, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.
1Erlang
1Erlang/otp
Nov 21, 2024
Dec 10, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow r...Show more
inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.Show less
2Debian
Yaws
2Debian Linux
Yaws
Nov 21, 2024
Dec 10, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable,...Show more
yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.Show less
2Fedoraproject
Kubernetes
2Fedora
Kubernetes
Nov 21, 2024
Dec 5, 2019
N/A· v4
2.6 LOW· v3
2.1 LOW· v2
Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted...Show more
Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the redirect as a GET request with client-certificate credentials for authenticating to the Kubelet.Show less
3Debian
FedoraprojectPython
3Debian Linux
FedoraPython
Nov 21, 2024
Nov 27, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
1Gitlab
1Gitlab
Jun 17, 2026
Nov 26, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redirect.
1Kaspersky
5Anti Virus
Internet SecuritySecurity Cloud+2 more
Jun 17, 2026
Nov 26, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequatel...Show more
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequately inform the user about the threat of redirecting to an untrusted site. Bypass.Show less
1Openidc
1Mod Auth Openidc
Jun 17, 2026
Nov 26, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with trailing slashes similar to CVE-2019-3877 in mod_auth_mellon.
1Posh Project
1Posh
Nov 21, 2024
Nov 22, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in the password reset functionality in POSH 3.0 through 3.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter...Show more
Open redirect vulnerability in the password reset functionality in POSH 3.0 through 3.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to portal/scr_sendmd5.php.Show less
1Openfind
1Mail2000
Jun 17, 2026
Nov 20, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malicious site without authentication. This vulnerability affects many mail system of governments, organiz...Show more
An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malicious site without authentication. This vulnerability affects many mail system of governments, organizations, companies and universities.Show less
1Blackboard
1Blackboard Learn
Nov 21, 2024
Nov 18, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing att...Show more
The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS server login page.Show less
1Popojicms
1Popojicms
Jun 17, 2026
Nov 7, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
PopojiCMS 2.0.1 allows refer= Open Redirection.
2Debian
Drupal
2Debian Linux
Drupal
Nov 21, 2024
Nov 6, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Drupal versions 5.x and 6.x has open redirection
1Typo3
1Typo3
Nov 21, 2024
Nov 4, 2019
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS and Open Redirection in the frontend login box.
1Typo3
1Typo3
Nov 21, 2024
Nov 1, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Open Redirection on the backend.
1Ibm
1Security Directory Server
Jun 17, 2026
Oct 2, 2019
N/A· v4
8.2 HIGH· v3
5.8 MEDIUM· v2
IBM Security Directory Server 6.4.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit...Show more
IBM Security Directory Server 6.4.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 165660.Show less
1Jetbrains
1Youtrack
Jun 17, 2026
Oct 1, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere.