← Back

CVE-2024-7211

nvd nist
Published: Aug 1, 2024Modified: May 20, 2025

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attacker to control the redirection path of end users. Note: 1E Platform's component utilizing the third-party Duende Identity Server has been updated with the patch that includes the fix.

Affected (4)

Products: 1e: Platform
1 product
Platform
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
1e
Version 23.11.1.15
Version 23.7.1.80
Version 24.7
Version 8.4.1.229

Timeline

No history available yet.