Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2020-05-07 CVE-2020-11053 Open Redirect vulnerability in Oauth2 Proxy Project Oauth2 Proxy
In OAuth2 Proxy before 5.1.1, there is an open redirect vulnerability.
network
low complexity
oauth2-proxy-project CWE-601
6.1
2020-05-06 CVE-2020-3311 Open Redirect vulnerability in Cisco Firepower Management Center
A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.
network
cisco CWE-601
5.8
2020-05-06 CVE-2020-3178 Open Redirect vulnerability in Cisco Content Security Management Appliance
Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.
network
cisco CWE-601
5.8
2020-05-05 CVE-2020-12666 Open Redirect vulnerability in multiple products
macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.com/ URL.
network
low complexity
go-macaron fedoraproject CWE-601
6.1
2020-05-05 CVE-2020-11034 Open Redirect vulnerability in Glpi-Project Glpi
In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp.
network
low complexity
glpi-project CWE-601
6.1
2020-05-04 CVE-2020-5337 Open Redirect vulnerability in RSA Archer
RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL redirection vulnerability.
network
rsa CWE-601
5.8
2020-05-01 CVE-2019-4209 Open Redirect vulnerability in Hcltech Connections 5.5/6.0/6.5
HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks.
network
hcltech CWE-601
5.8
2020-04-30 CVE-2020-12283 Open Redirect vulnerability in Sourcegraph
Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/redirect.go, such as for the //foo//example.com substring.
5.8
2020-04-20 CVE-2020-5270 Open Redirect vulnerability in Prestashop
In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is an open redirection when using back parameter.
5.8
2020-04-17 CVE-2020-5733 Open Redirect vulnerability in Openmrs
In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user attempts to access it.
network
openmrs CWE-601
5.8