Maven package
org.wso2.carbon.identity.framework/org.wso2.carbon.identity.application.authentication.endpoint.util
pkg:maven/org.wso2.carbon.identity.framework/org.wso2.carbon.identity.application.authentication.endpoint.util
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-1440 | Med | 5.4 | >= 6.0.0, < 7.0.111 | 7.0.111 | Jun 2, 2025 | An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlle |
- affected >= 6.0.0, < 7.0.111fixed 7.0.111
An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlle