The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attacker to control the redirection path of end users.
Note: 1E Platform's component utilizing the third-party Duende Identity Server has been updated with the patch that includes the fix.
References
Link | Resource |
---|---|
https://www.1e.com/trust-security-compliance/cve-info/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-08-01 17:16
Updated : 2025-03-13 17:15
NVD link : CVE-2024-7211
Mitre link : CVE-2024-7211
CVE.ORG link : CVE-2024-7211
JSON object : View
Products Affected
1e
- platform
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')