Weaknesses of type CWE-601

1,187 results

Redirecionamento aberto para site não confiável

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (ou por um atacante) sem validação prévia. O navegador segue o redirecionamento automaticamente, levando a vítima para um site malicioso que pode clonar a interface legítima para roubar credenciais ou distribuir malware, com aparência de vir de um domínio confiável.

Example

Um link do tipo `https://banco.com/redirect?url=https://banco-falso.com` recebe a URL de destino como parâmetro e redireciona direto sem checagem. Atacante envia `https://banco.com/redirect?url=https://phishing.com` em email, e a vítima clica pensando estar acessando o banco.

How to mitigate

Valide sempre a URL de destino contra uma lista branca de domínios permitidos ou use URLs relativas. Se aceitar redirecionamentos dinâmicos, verifique que o host pertence ao seu domínio ou a uma lista explícita de parceiros confiáveis.

CVE-2022-38662MEDIUMHCL Digital Experience is susceptible to open redirectsEPSS 0.4%CVE-2026-59730LOW@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirectEPSS 0.4%CVE-2024-11207MEDIUMApereo CAS login redirectEPSS 0.4%CVE-2024-7428MEDIUMPotential Open Redirect issues affect OpenText™ Network Node Manager i (NNMi).EPSS 0.4%CVE-2026-88880CRITICALRenovate before 44.11.3 Credential Exfiltration via Link HeaderEPSS 0.4%CVE-2022-29910MEDIUMWhen closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.<br>*Note: This issue only afEPSS 0.4%CVE-2023-39371HIGH StarTrinity Softswitch version 2023-02-16 – Open Redirect (CWE-601)EPSS 0.4%CVE-2023-1279LOWURL Redirection to Untrusted Site in GitLabEPSS 0.4%CVE-2023-23860MEDIUMSAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attaEPSS 0.4%CVE-2022-1230LOWThis vulnerability allows local attackers to execute arbitrary code on affected installations of Samsung Galaxy S21 prior to 4.5.40.5 phonesEPSS 0.4%CVE-2023-28786LOWWordPress Solid Security Plugin <= 8.1.4 is vulnerable to Open RedirectionEPSS 0.4%CVE-2024-25609MEDIUMHtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 sEPSS 0.4%CVE-2026-46796HIGHVulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are aEPSS 0.4%CVE-2026-48589NONEApache Shiro: Jakarta EE open redirect via untrusted Referer in post-login redirect flowEPSS 0.4%CVE-2024-8412MEDIUMLinuxOSsk Shakal-NG views.py redirectEPSS 0.4%CVE-2026-60632CRITICALVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.4%CVE-2026-12863MEDIUMOpen redirectEPSS 0.4%CVE-2023-32517MEDIUMWordPress MailChimp Subscribe Forms Plugin <= 4.0.9.3 is vulnerable to Open RedirectionEPSS 0.4%CVE-2025-31871MEDIUMWordPress WP Clone any post type Plugin <= 3.6 - Open Redirect vulnerabilityEPSS 0.4%CVE-2025-27143MEDIUMBeter Auth has an Open Redirect via Scheme-Less Callback ParameterEPSS 0.4%