An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlled site.

By exploiting this vulnerability, an attacker may trick users into visiting a malicious page, enabling phishing attacks to harvest sensitive information or perform other harmful actions.

Project Subscriptions

Vendors Products
Api Manager Subscribe
Identity Server Subscribe
Identity Server As Key Manager Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-17193 An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlled site. By exploiting this vulnerability, an attacker may trick users into visiting a malicious page, enabling phishing attacks to harvest sensitive information or perform other harmful actions.
Github GHSA Github GHSA GHSA-cp5v-2hmc-3vjx WSO2 is vulnerable to Open Redirect through multi-option URL in its authentication endpoint
Fixes

Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3... https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2024/WSO2-2024-3171/#solution


Workaround

No workaround given by the vendor.

History

Mon, 06 Oct 2025 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Wso2
Wso2 api Manager
Wso2 identity Server
Wso2 identity Server As Key Manager
CPEs cpe:2.3:a:wso2:api_manager:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:5.10.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:5.11.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server_as_key_manager:5.10.0:*:*:*:*:*:*:*
Vendors & Products Wso2
Wso2 api Manager
Wso2 identity Server
Wso2 identity Server As Key Manager

Mon, 02 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 02 Jun 2025 17:00:00 +0000

Type Values Removed Values Added
Description An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlled site. By exploiting this vulnerability, an attacker may trick users into visiting a malicious page, enabling phishing attacks to harvest sensitive information or perform other harmful actions.
Title Open Redirection in Multiple WSO2 Products via Multi-Option Authentication Endpoint
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2025-06-02T17:07:01.605Z

Reserved: 2024-02-12T09:53:51.193Z

Link: CVE-2024-1440

cve-icon Vulnrichment

Updated: 2025-06-02T17:06:54.680Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-02T17:15:21.153

Modified: 2025-10-06T13:48:42.233

Link: CVE-2024-1440

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses