Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.
SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insuff
IBM Security Verify Access 10.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack
Open Redirect in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
A vulnerability was found in Symbiote Seed up to 6.0.2. It has been classified as critical. Affected is the function onB
A vulnerability, which was classified as critical, has been found in Freshdesk Plugin 1.7 on WordPress. Affected by this
Open Redirect in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypa
The Syracom Secure Login plugin before 3.1.1.0 for Jira may allow spoofing of 2FA PIN validation via the plugins/servlet
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15
Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a
A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to
Jenkins OpenID Plugin 2.4 and earlier improperly determines that a redirect URL after login is legitimately pointing to
On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versio
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phi
An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling red
Prior to commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0, https://github.com/brave/adblock-lists removed redirect interc
An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740,
SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an
open redirect in pollbot (pollbot.services.mozilla.com) in versions before 1.4.6
An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if th
SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection. (The issue was originally found in 5.5.
A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domai
Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirec
PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerabil
A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerab
Dell Streaming Data Platform prior to 1.4 contains Open Redirect vulnerability. A remote unauthenticated attacker can p
Microsoft Edge (Chromium-based) Spoofing Vulnerability
lorawan-stack is an open source LoRaWAN network server. Prior to version 3.24.1, an open redirect exists on the login pa
Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php.
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthe
Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated m
An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue w
Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in s
Landscape allowed URLs which caused open redirection.
Keystone is a content management system for Node.JS. There is an open redirect in the `@keystone-6/auth` package version
Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Li
An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0 and 8.8.15. To e
When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox
Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect.
An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android
The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL
yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external down
Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier improperly determines that a redirect URL after log
Open redirect vulnerability in ELECOM wireless LAN routers and ELECOM wireless LAN repeaters allows a remote unauthentic
SeedDMS v6.0.15 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to
Netdisco before v2.063000 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnera
Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the refere
Frequently Asked Questions
What is CWE-601?
CWE-601 (CWE-601) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-601?
There are 1,953 CVE records associated with CWE-601 in our database. Of these, 31 are critical severity, 165 are high severity, and 1323 are medium severity.
How can I protect against CWE-601 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-601 using AI-powered security agents.
Detect CWE-601 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-601 vulnerabilities across your infrastructure.
Get Started