{"id":"CVE-2024-1440","aliases":["GHSA-cp5v-2hmc-3vjx"],"url":"https://o3.security/vulnerability/CVE-2024-1440","summary":"WSO2 is vulnerable to Open Redirect through multi-option URL in its authentication endpoint","details":"An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlled site.\n\nBy exploiting this vulnerability, an attacker may trick users into visiting a malicious page, enabling phishing attacks to harvest sensitive information or perform other harmful actions.","published":"2025-06-02T17:15:21.153Z","modified":"2026-07-08T08:05:28.933370385Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.util","fixedVersion":"7.0.111"},{"ecosystem":"Maven","name":"org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.util","fixedVersion":"5.25.707"}],"fix":{"url":"https://github.com/wso2/carbon-identity-framework/pull/5580","label":"wso2/carbon-identity-framework#5580"},"references":[{"type":"ADVISORY","url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3171/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-1440"},{"type":"WEB","url":"https://github.com/wso2/carbon-identity-framework/pull/5580"},{"type":"WEB","url":"https://github.com/wso2/carbon-identity-framework/pull/5747"},{"type":"WEB","url":"https://github.com/wso2/carbon-identity-framework/commit/29ea34ada98649c4ae71aa92f1cbe87ce82164b9"},{"type":"WEB","url":"https://github.com/wso2/carbon-identity-framework/commit/7033924b6d53ff843529743b259f6c48f4e9c177"},{"type":"PACKAGE","url":"https://github.com/wso2/carbon-identity-framework"},{"type":"WEB","url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3171"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T08:05:28.933370385Z"}}