CVE-2024-1440
MEDIUMWSO2 API Manager and Identity Server - Open Redirect via Multi-Option Authentication Endpoint
Title source: llmDescription
An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlled site. By exploiting this vulnerability, an attacker may trick users into visiting a malicious page, enabling phishing attacks to harvest sensitive information or perform other harmful actions.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3171/
Scores
CVSS v3
5.4
EPSS
0.0020
EPSS Percentile
10.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-601
Status
published
Products (10)
org.wso2.carbon.identity.framework/org.wso2.carbon.identity.application.authentication.endpoint.util
6.0.0 - 7.0.111Maven
wso2/api_manager
3.1.0
wso2/api_manager
3.2.0
wso2/api_manager
4.0.0
wso2/identity_server
5.10.0
wso2/identity_server
5.11.0
wso2/identity_server
6.0.0
wso2/identity_server
6.1.0
wso2/identity_server
7.0.0
wso2/identity_server_as_key_manager
5.10.0
Published
Jun 02, 2025
Tracked Since
Feb 18, 2026