Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2019-08-23 CVE-2019-11589 Open Redirect vulnerability in Atlassian Jira Server
The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to attack users, in some cases be able to obtain a user's Cross-site request forgery (CSRF) token, via a open redirect vulnerability.
network
low complexity
atlassian CWE-601
6.1
2019-08-23 CVE-2019-11585 Open Redirect vulnerability in Atlassian Jira
The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.
network
low complexity
atlassian CWE-601
6.1
2019-08-07 CVE-2019-10372 Open Redirect vulnerability in Jenkins Gitlab Oauth
An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows attackers to redirect users to a URL outside Jenkins after successful login.
network
low complexity
jenkins CWE-601
6.1
2019-08-05 CVE-2016-10769 Open Redirect vulnerability in Cpanel
cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).
network
low complexity
cpanel CWE-601
6.1
2019-08-02 CVE-2017-18441 Open Redirect vulnerability in Cpanel
cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245).
network
low complexity
cpanel CWE-601
5.0
2019-08-02 CVE-2017-18414 Open Redirect vulnerability in Cpanel
cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).
network
low complexity
cpanel CWE-601
7.4
2019-08-01 CVE-2019-9140 Open Redirect vulnerability in Happypointcard Happypoint 6.3.19
When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly.
network
low complexity
happypointcard CWE-601
8.1
2019-08-01 CVE-2018-20929 Open Redirect vulnerability in Cpanel
cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392).
network
low complexity
cpanel CWE-601
6.1
2019-07-30 CVE-2019-14403 Open Redirect vulnerability in Cpanel
cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).
network
low complexity
cpanel CWE-601
4.3
2019-07-30 CVE-2018-20867 Open Redirect vulnerability in Cpanel
cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).
network
low complexity
cpanel CWE-601
6.1