Description
The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attacker to control the redirection path of end users.
Note: 1E Platform's component utilizing the third-party Duende Identity Server has been updated with the patch that includes the fix.
Note: 1E Platform's component utilizing the third-party Duende Identity Server has been updated with the patch that includes the fix.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48178 | The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attacker to control the redirection path of end users. Note: 1E Platform's component utilizing the third-party Duende Identity Server has been updated with the patch that includes the fix. |
References
History
Tue, 20 May 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 20 May 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 06 Sep 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
1e
1e platform |
|
| Weaknesses | CWE-601 | |
| CPEs | cpe:2.3:a:1e:platform:23.11.1.15:*:*:*:*:*:*:* cpe:2.3:a:1e:platform:23.7.1.80:*:*:*:*:*:*:* cpe:2.3:a:1e:platform:24.7:*:*:*:*:*:*:* cpe:2.3:a:1e:platform:8.4.1.229:*:*:*:*:*:*:* |
|
| Vendors & Products |
1e
1e platform |
Status: PUBLISHED
Assigner: 1E
Published:
Updated: 2025-06-18T18:41:03.926Z
Reserved: 2024-07-29T16:05:07.068Z
Link: CVE-2024-7211
Updated: 2024-08-01T17:33:33.282Z
Status : Modified
Published: 2024-08-01T17:16:09.727
Modified: 2025-05-20T09:15:20.953
Link: CVE-2024-7211
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD