Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-1440

Опубликовано: 02 июн. 2025
Источник: nvd
CVSS3: 5.4
CVSS3: 6.1
EPSS Низкий

Описание

An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlled site.

By exploiting this vulnerability, an attacker may trick users into visiting a malicious page, enabling phishing attacks to harvest sensitive information or perform other harmful actions.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:wso2:api_manager:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:5.10.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:5.11.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server_as_key_manager:5.10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 12%
0.00039
Низкий

5.4 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 5.4
github
8 месяцев назад

WSO2 is vulnerable to Open Redirect through multi-option URL in its authentication endpoint

EPSS

Процентиль: 12%
0.00039
Низкий

5.4 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-601