PT-2024-38171 · Duende+1 · Duende Identityserver+1
Published
2024-08-01
·
Updated
2025-05-20
·
CVE-2024-7211
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
1E Platform (affected versions not specified)
Duende Identity Server (affected versions not specified)
Description
The issue concerns an open redirect vulnerability in the Duende Identity Server, a third-party component used by the 1E Platform. This vulnerability allows an attacker to control the redirection path of end users, potentially redirecting them to untrusted sites.
Recommendations
For the 1E Platform, update the component utilizing the Duende Identity Server with the patch that includes the fix.
For the Duende Identity Server, apply the necessary patch to resolve the issue.
As a temporary workaround, consider restricting URL redirection to trusted sites until the patch is applied.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
1E Platform
Duende Identityserver