The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attacker to control the redirection path of end users.
Note: 1E Platform's component utilizing the third-party Duende Identity Server has been updated with the patch that includes the fix.
References
Configurations
Configuration 1 (hide)
|
History
20 May 2025, 09:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2024-08-01 17:16
Updated : 2025-05-20 09:15
NVD link : CVE-2024-7211
Mitre link : CVE-2024-7211
CVE.ORG link : CVE-2024-7211
JSON object : View
Products Affected
1e
- platform
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')