Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.wso2.carbon.identity.framework/org.wso2.carbon.identity.application.authentication.endpoint.util
  4. ›
  5. CVE-2024-1440

CVE-2024-1440: WSO2 is vulnerable to Open Redirect through multi-option URL in its authentication endpoint

June 2, 2025 (updated October 7, 2025)

An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlled site.

By exploiting this vulnerability, an attacker may trick users into visiting a malicious page, enabling phishing attacks to harvest sensitive information or perform other harmful actions.

References

  • github.com/advisories/GHSA-cp5v-2hmc-3vjx
  • github.com/wso2/carbon-identity-framework
  • github.com/wso2/carbon-identity-framework/commit/29ea34ada98649c4ae71aa92f1cbe87ce82164b9
  • github.com/wso2/carbon-identity-framework/commit/7033924b6d53ff843529743b259f6c48f4e9c177
  • github.com/wso2/carbon-identity-framework/pull/5580
  • github.com/wso2/carbon-identity-framework/pull/5747
  • nvd.nist.gov/vuln/detail/CVE-2024-1440
  • security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3171

Code Behaviors & Features

Detect and mitigate CVE-2024-1440 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 5.25.707, all versions starting from 6.0.0 before 7.0.111

Fixed versions

  • 7.0.111
  • 5.25.707

Solution

Upgrade to versions 5.25.707, 7.0.111 or above.

Impact 5.4 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Source file

maven/org.wso2.carbon.identity.framework/org.wso2.carbon.identity.application.authentication.endpoint.util/CVE-2024-1440.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sun, 09 Nov 2025 12:20:21 +0000.