Unauthenticated redirection to a malicious website
An open redirect vulnerability exists in CERT/CC VINCE software prior to 1.50.0. An attacker could send a link that has
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an atta
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to tr
IBM Security Identity Manager 6.0 and 6.0.2 could allow a remote attacker to conduct phishing attacks, using an open red
RStudio Connect prior to 2023.01.0 is affected by an Open Redirect issue. The vulnerability could allow an attacker to r
In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter.
OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601)
In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint.
HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack
Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.
Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing att
Esri ArcGIS Server versions 10.9.1 and below have an unvalidated redirect issue that may allow a remote, unauthenticated
U-Office Force login function has an Open Redirect vulnerability. An unauthenticated remote attacker can exploit this vu
In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint.
SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting
In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint.
An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.
An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously cr
Open redirect vulnerability in SHIRASAGI v1.14.4 to v1.15.0 allows a remote unauthenticated attacker to redirect users t
ILIAS before 7.16 has an Open Redirect.
Jenkins Google Login Plugin 1.4 through 1.6 (both inclusive) improperly determines that a redirect URL after login is le
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Hewlett Packard Enterprise HPE OneView Global Dashb
In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link tha
Open redirect vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to
In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI componen
Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.4.
When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.<br>*Note
Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affec
Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect h
When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus le
Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause
Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.5.
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11 and below that may allow a remote, unauthent
OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Open
A vulnerability has been found in cyface Terms and Conditions Module up to 2.0.9 and classified as problematic. Affected
A vulnerability was found in Macaron i18n. It has been declared as problematic. Affected by this vulnerability is an unk
Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameter
The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parame
Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter.
A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the
Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivileged attacker may po
OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability.
OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.
An open redirect vulnerability in the administrative interface of the B. Braun Melsungen AG SpaceCom device Version L81/
This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect
This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next qu
Intent redirection vulnerability using implict intent in Camera prior to versions 12.0.01.64 ,12.0.3.23, 12.0.0.98, 12.0
Frequently Asked Questions
What is CWE-601?
CWE-601 (CWE-601) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-601?
There are 1,953 CVE records associated with CWE-601 in our database. Of these, 31 are critical severity, 165 are high severity, and 1323 are medium severity.
How can I protect against CWE-601 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-601 using AI-powered security agents.
Detect CWE-601 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-601 vulnerabilities across your infrastructure.
Get Started