VYPR
Medium severity5.4NVD Advisory· Published Jun 2, 2025· Updated Jun 17, 2026

CVE-2024-1440

CVE-2024-1440

Description

An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlled site.

By exploiting this vulnerability, an attacker may trick users into visiting a malicious page, enabling phishing attacks to harvest sensitive information or perform other harmful actions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.utilMaven
>= 6.0.0, < 7.0.1117.0.111
org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.utilMaven
< 5.25.7075.25.707

Affected products

7

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.