Weaknesses of type CWE-601

1,183 results

Redirecionamento aberto para site não confiável

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (ou por um atacante) sem validação prévia. O navegador segue o redirecionamento automaticamente, levando a vítima para um site malicioso que pode clonar a interface legítima para roubar credenciais ou distribuir malware, com aparência de vir de um domínio confiável.

Example

Um link do tipo `https://banco.com/redirect?url=https://banco-falso.com` recebe a URL de destino como parâmetro e redireciona direto sem checagem. Atacante envia `https://banco.com/redirect?url=https://phishing.com` em email, e a vítima clica pensando estar acessando o banco.

How to mitigate

Valide sempre a URL de destino contra uma lista branca de domínios permitidos ou use URLs relativas. Se aceitar redirecionamentos dinâmicos, verifique que o host pertence ao seu domínio ou a uma lista explícita de parceiros confiáveis.

CVE-2024-25608MEDIUMHtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 EPSS 1.0%CVE-2017-6018An open redirect issue was discovered in B. Braun Medical SpaceCom module, which is integrated into the SpaceStation docking station: SpaceSEPSS 1.0%CVE-2023-6291HIGHKeycloak: redirect_uri validation bypassEPSS 0.9%CVE-2021-21392MEDIUMOpen redirect via transitional IPv6 addresses on dual-stack networksEPSS 0.9%CVE-2022-43479MEDIUMOpen redirect vulnerability in SHIRASAGI v1.14.4 to v1.15.0 allows a remote unauthenticated attacker to redirect users to an arbitrary web sEPSS 0.9%CVE-2022-24887MEDIUMOpen Redirect in Nextcloud TalkEPSS 0.9%CVE-2020-7520A CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability exists in Schneider Electric Software Update (SESU), V2.4.0 andEPSS 0.9%CVE-2018-3743Open redirect in hekto <=0.2.3 when target domain name is used as html filename on server.EPSS 0.9%CVE-2022-2252MEDIUMOpen Redirect in microweber/microweberEPSS 0.9%CVE-2023-22298MEDIUMOpen redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a user to an arbitraryEPSS 0.9%CVE-2022-24739HIGHServer-Side Request Forgery (SSRF) and URL Redirection to Untrusted Site ('Open Redirect') in alltubeEPSS 0.9%CVE-2021-3647MEDIUMOpen Redirect in medialize/URI.jsEPSS 0.9%CVE-2020-5409HIGHConcourse Open Redirect in the /sky/login endpointEPSS 0.9%CVE-2017-8451With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to cEPSS 0.9%CVE-2019-10133LOWA flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not EPSS 0.9%CVE-2022-23527MEDIUMOpen Redirect in oidc_validate_redirect_url()EPSS 0.9%CVE-2020-4037MEDIUMOpen Redirect in OAuth2 ProxyEPSS 0.9%CVE-2020-1997MEDIUMPAN-OS: GlobalProtect registration open redirectEPSS 0.9%CVE-2017-16224st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely differEPSS 0.9%CVE-2019-13422Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the user to a potentially EPSS 0.9%