Weaknesses of type CWE-601

1,184 results

Redirecionamento aberto para site não confiável

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (ou por um atacante) sem validação prévia. O navegador segue o redirecionamento automaticamente, levando a vítima para um site malicioso que pode clonar a interface legítima para roubar credenciais ou distribuir malware, com aparência de vir de um domínio confiável.

Example

Um link do tipo `https://banco.com/redirect?url=https://banco-falso.com` recebe a URL de destino como parâmetro e redireciona direto sem checagem. Atacante envia `https://banco.com/redirect?url=https://phishing.com` em email, e a vítima clica pensando estar acessando o banco.

How to mitigate

Valide sempre a URL de destino contra uma lista branca de domínios permitidos ou use URLs relativas. Se aceitar redirecionamentos dinâmicos, verifique que o host pertence ao seu domínio ou a uma lista explícita de parceiros confiáveis.

CVE-2023-25734HIGHAfter downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to EPSS 0.8%CVE-2024-10908MEDIUMOpen Redirect in lm-sys/fastchatEPSS 0.8%CVE-2022-21651MEDIUMOpen redirect in shopwareEPSS 0.8%CVE-2020-15242MEDIUMOpen Redirect in Next.jsEPSS 0.8%CVE-2021-3989MEDIUMOpen Redirect in star7th/showdocEPSS 0.8%CVE-2024-13888HIGHWPMobile.App <= 11.56 - Open Redirect via 'redirect' ParameterEPSS 0.8%CVE-2026-47645HIGHMicrosoft 365 Copilot's Business Chat Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2020-5337MEDIUMRSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL redirection vulnerability. A remote unauthenticated attacker could potentiallyEPSS 0.8%CVE-2023-39364LOWOpen redirect in change password functionality in CactiEPSS 0.7%CVE-2024-8021MEDIUMOpen Redirect in gradio-app/gradioEPSS 0.7%CVE-2022-24794HIGHOpen Redirect in express-openid-connectEPSS 0.7%CVE-2017-11482The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open rediEPSS 0.7%CVE-2022-20794MEDIUMCisco TelePresence Collaboration Endpoint and RoomOS Software VulnerabilitiesEPSS 0.7%CVE-2017-20119LOWTrueConf Server change-lang redirectEPSS 0.7%CVE-2021-40852MEDIUMTCMAN GIM open redirect vulnerabilityEPSS 0.7%CVE-2022-1209MEDIUMUltimate Member <= 2.3.1 - Arbitrary RedirectEPSS 0.7%CVE-2022-0868HIGHOpen Redirect in medialize/uri.jsEPSS 0.7%CVE-2005-10001MEDIUMNetegrity SiteMinder Login smpwservicescgi.exe redirectEPSS 0.7%CVE-2022-31151LOWUncleared cookies on cross-host/cross-origin redirect in undiciEPSS 0.7%CVE-2026-41106CRITICALMicrosoft 365 Copilot Elevation of Privilege VulnerabilityEPSS 0.7%