{"id":"CVE-2024-1440","aliases":["GHSA-cp5v-2hmc-3vjx"],"url":"https://o3.security/vulnerability/CVE-2024-1440","summary":"WSO2 is vulnerable to Open Redirect through multi-option URL in its authentication endpoint","details":"An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlled site.\n\nBy exploiting this vulnerability, an attacker may trick users into visiting a malicious page, enabling phishing attacks to harvest sensitive information or perform other harmful actions.","published":"2025-06-02T17:15:21.153Z","modified":"2026-07-08T08:05:28.933370385Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.util","fixedVersion":"7.0.111"},{"ecosystem":"Maven","name":"org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.util","fixedVersion":"5.25.707"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3171/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T08:05:28.933370385Z"}}