VYPR

Maven package

org.wso2.carbon.identity.framework/org.wso2.carbon.identity.application.authentication.endpoint.util

pkg:maven/org.wso2.carbon.identity.framework/org.wso2.carbon.identity.application.authentication.endpoint.util

Vulnerabilities (1)

  • CVE-2024-1440MedJun 2, 2025
    affected >= 6.0.0, < 7.0.111fixed 7.0.111

    An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlle