CVE-2024-7211

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
01/08/2024
Last modified:
20/05/2025

Description

The 1E Platform&amp;#39;s component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attacker to control the redirection path of end users.<br /> <br /> Note: 1E Platform&amp;#39;s component utilizing the third-party Duende Identity Server has been updated with the patch that includes the fix.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:1e:platform:8.4.1.229:*:*:*:*:*:*:*
cpe:2.3:a:1e:platform:23.7.1.80:*:*:*:*:*:*:*
cpe:2.3:a:1e:platform:23.11.1.15:*:*:*:*:*:*:*
cpe:2.3:a:1e:platform:24.7:*:*:*:*:*:*:*