Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2019-06-29 CVE-2019-13038 Open Redirect vulnerability in multiple products
mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.
6.1
2019-06-27 CVE-2019-5823 Open Redirect vulnerability in multiple products
Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
network
low complexity
google opensuse debian fedoraproject CWE-601
5.4
2019-06-26 CVE-2019-10133 Open Redirect vulnerability in Moodle
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18.
network
low complexity
moodle CWE-601
6.1
2019-06-25 CVE-2019-4153 Open Redirect vulnerability in IBM Security Access Manager
IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
low complexity
ibm CWE-601
6.8
2019-06-19 CVE-2017-14394 Open Redirect vulnerability in Forgerock Access Management and Openam
OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to perform phishing via an unvalidated redirect.
network
low complexity
forgerock CWE-601
6.1
2019-06-12 CVE-2019-11269 Open Redirect vulnerability in multiple products
Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code.
network
low complexity
pivotal-software oracle CWE-601
5.4
2019-06-07 CVE-2019-3477 Open Redirect vulnerability in Microfocus Solutions Business Manager
Micro Focus Solution Business Manager versions prior to 11.4.2 is susceptible to open redirect.
network
low complexity
microfocus CWE-601
6.1
2019-06-06 CVE-2019-4201 Open Redirect vulnerability in IBM Jazz for Service Management
IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
low complexity
ibm CWE-601
6.1
2019-06-04 CVE-2018-13384 Open Redirect vulnerability in Fortinet Fortios
A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequently redirect SSL VPN web portal users to arbitrary web domains.
network
low complexity
fortinet CWE-601
6.1
2019-06-03 CVE-2019-6741 Open Redirect vulnerability in Samsung Galaxy S9 Firmware 1.4.20.2
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to January 2019 Security Update (SMR-JAN-2019 - SVE-2018-13467).
network
low complexity
samsung CWE-601
critical
9.3