« Volver al listado

CVE-2024-1440

Estado: AnalizadaMedia (6.1)—

An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlled site.

By exploiting this vulnerability, an attacker may trick users into visiting a malicious page, enabling phishing attacks to harvest sensitive information or perform other harmful actions.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-1440",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-1440",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-06-02T17:06:49.114728Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
      "affectedData": [
        {
          "vendor": "WSO2",
          "product": "WSO2 Identity Server",
          "versions": [
            {
              "status": "unknown",
              "version": "0",
              "lessThan": "5.10.0",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "5.10.0",
              "lessThan": "5.10.0.278",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "5.11.0",
              "lessThan": "5.11.0.347",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "6.0.0",
              "lessThan": "6.0.0.185",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "6.1.0",
              "lessThan": "6.1.0.145",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "7.0.0",
              "lessThan": "7.0.0.30",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WSO2",
          "product": "WSO2 API Manager",
          "versions": [
            {
              "status": "unknown",
              "version": "0",
              "lessThan": "3.1.0",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.1.0",
              "lessThan": "3.1.0.262",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.2.0",
              "lessThan": "3.2.0.344",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.0.0",
              "lessThan": "4.0.0.296",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WSO2",
          "product": "WSO2 Identity Server as Key Manager",
          "versions": [
            {
              "status": "unknown",
              "version": "0",
              "lessThan": "5.10.0",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "5.10.0",
              "lessThan": "5.10.0.298",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WSO2",
          "product": "WSO2 Open Banking AM",
          "versions": [
            {
              "status": "unknown",
              "version": "0",
              "lessThan": "2.0.0",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.0.0",
              "lessThan": "2.0.0.308",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WSO2",
          "product": "WSO2 Open Banking IAM",
          "versions": [
            {
              "status": "unknown",
              "version": "0",
              "lessThan": "2.0.0",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.0.0",
              "lessThan": "2.0.0.327",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "WSO2",
          "product": "WSO2 Carbon Identity Application Authentication Endpoint(Utils)",
          "versions": [
            {
              "status": "affected",
              "version": "5.17.5",
              "lessThan": "5.17.5.256",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "5.18.187",
              "lessThan": "5.18.187.257",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "5.23.8",
              "lessThan": "5.23.8.174",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "5.25.92",
              "lessThan": "5.25.92.77",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "7.0.78",
              "lessThan": "7.0.78.18",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "7.0.111",
              "versionType": "custom",
              "lessThanOrEqual": "*"
            }
          ],
          "packageName": "org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.endpoint.util",
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2025-06-02T17:15:21.153",
  "references": [
    {
      "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3171/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
      "description": [
        {
          "lang": "en",
          "value": "CWE-601"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlled site.\n\nBy exploiting this vulnerability, an attacker may trick users into visiting a malicious page, enabling phishing attacks to harvest sensitive information or perform other harmful actions."
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad de redirección abierta en varios productos WSO2 debido a la validación incorrecta de la URL multiopción en el endpoint de autenticación cuando esta está habilitada. Un atacante puede crear un enlace válido que redirija a los usuarios a un sitio web controlado por el atacante. Al explotar esta vulnerabilidad, un atacante puede engañar a los usuarios para que visiten una página maliciosa, lo que permite ataques de phishing para recopilar información confidencial o realizar otras acciones dañinas."
    }
  ],
  "lastModified": "2026-06-17T07:04:14.970",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wso2:api_manager:3.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1344FB79-0796-445C-A8F3-C03E995925D1"
            },
            {
              "criteria": "cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E31E32CD-497E-4EF5-B3FC-8718EE06EDAD"
            },
            {
              "criteria": "cpe:2.3:a:wso2:api_manager:4.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E21D7ABF-C328-425D-B914-618C7628220B"
            },
            {
              "criteria": "cpe:2.3:a:wso2:identity_server:5.10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F4F126CA-A2F9-44F4-968B-DF71765869E5"
            },
            {
              "criteria": "cpe:2.3:a:wso2:identity_server:5.11.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2153AECE-020A-4C01-B2A6-F9F5D98E7EBE"
            },
            {
              "criteria": "cpe:2.3:a:wso2:identity_server:6.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B81C488-69D0-4A5C-AEED-31869C1BF5CA"
            },
            {
              "criteria": "cpe:2.3:a:wso2:identity_server:6.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "65CD2558-C60C-4296-8E96-D4D804C598F0"
            },
            {
              "criteria": "cpe:2.3:a:wso2:identity_server:7.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8DF49C6-F2F6-4229-982E-0C0559265203"
            },
            {
              "criteria": "cpe:2.3:a:wso2:identity_server_as_key_manager:5.10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6BB34405-A2F1-461A-B51B-E103BB3680A1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
}