← voltar
CVE-2024-7211mediumCWE-601

The Duende Identity Server based component in 1E Platform may allow URL redirections to untrusted websites.

13Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 4.7epss 0.2%
probabilidade de exploração
0.2%top 85% das CVEs
exploração observada
nãonenhuma fonte reporta
The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attacker to control the redirection path of end users. Note: 1E Platform's component utilizing the third-party Duende Identity Server has been updated with the patch that includes the fix.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Produtos afetados
1E · 1E Platform