Medium severity5.4NVD Advisory· Published Jun 2, 2025· Updated Jun 17, 2026
CVE-2024-1440
CVE-2024-1440
Description
An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlled site.
By exploiting this vulnerability, an attacker may trick users into visiting a malicious page, enabling phishing attacks to harvest sensitive information or perform other harmful actions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.utilMaven | >= 6.0.0, < 7.0.111 | 7.0.111 |
org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.utilMaven | < 5.25.707 | 5.25.707 |
Affected products
7- ghsa-coordsRange: >= 6.0.0, < 7.0.111
- WSO2/WSO2 API Managerv5Range: 3.1.0
- WSO2/WSO2 Carbon Identity Application Authentication Endpoint(Utils)v5Range: 5.17.5
- WSO2/WSO2 Identity Serverv5Range: 5.10.0
- WSO2/WSO2 Identity Server as Key Managerv5Range: 5.10.0
- WSO2/WSO2 Open Banking AMv5Range: 2.0.0
- WSO2/WSO2 Open Banking IAMv5Range: 2.0.0
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-cp5v-2hmc-3vjxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-1440ghsaADVISORY
- security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3171/nvdVendor Advisory
- github.com/wso2/carbon-identity-framework/commit/29ea34ada98649c4ae71aa92f1cbe87ce82164b9ghsaWEB
- github.com/wso2/carbon-identity-framework/commit/7033924b6d53ff843529743b259f6c48f4e9c177ghsaWEB
- github.com/wso2/carbon-identity-framework/pull/5580ghsaWEB
- github.com/wso2/carbon-identity-framework/pull/5747ghsaWEB
- security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3171ghsaWEB
News mentions
0No linked articles in our index yet.