Open Redirection Vulnerability in WSO2 Products
CVE-2024-1440
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 2 June 2025
What is CVE-2024-1440?
An open redirection vulnerability arises in various WSO2 products due to inadequate validation of the multi-option URL within the authentication endpoint when multi-option authentication is activated. This flaw allows malicious individuals to create valid links that redirect users to sites under their control. By exploiting this vulnerability, attackers can potentially deceive users into visiting harmful pages, facilitating phishing attempts to gather sensitive data or execute other malicious activities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WSO2 API Manager 3.1.0 < 3.1.0.262
WSO2 API Manager 3.2.0 < 3.2.0.344
WSO2 API Manager 4.0.0 < 4.0.0.296
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
