CVE-2024-39694
Last modified
CVE-2024-39694 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to craft malicious Urls that certain functions in IdentityServer will incorrectly treat as local and trusted. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to craft malicious Urls that certain functions in IdentityServer will incorrectly treat as local and trusted. If such a Url is returned as a redirect, some browsers will follow it to a third-party, untrusted site. Note: by itself, this vulnerability does **not** allow an attacker to obtain user credentials, authorization codes, access tokens, refresh tokens, or identity tokens. An attacker could however exploit this vulnerability as part of a phishing attack designed to steal user credentials. This vulnerability is fixed in 7.0.6, 6.3.10, 6.2.5, 6.1.8, and 6.0.5. Duende.IdentityServer 5.1 and earlier and all versions of IdentityServer4 are no longer supported and will not be receiving updates. If upgrading is not possible, use `IUrlHelper.IsLocalUrl` from ASP.NET Core to validate return Urls in user interface code in the IdentityServer host.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-39694?
How severe is CVE-2024-39694?
How do I fix CVE-2024-39694?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-39688Bert-VITS2 is the VITS2 Backbone with multilingual bert. Use…6.5
- CVE-2024-39689Certifi is a curated collection of Root Certificates for val…7.5
- CVE-2024-3969XML External Entity injection vulnerability found in OpenTex…9.8
- CVE-2024-39690Capsule is a multi-tenancy and policy-based framework for Ku…8.8
- CVE-2024-39691matrix-appservice-irc is a Node.js IRC bridge for the Matrix…4.3
- CVE-2024-39693Next.js is a React framework. A Denial of Service (DoS) cond…7.5
- CVE-2024-39695Exiv2 is a command-line utility and C++ library for reading,…6.5
- CVE-2024-39696Evmos is a decentralized Ethereum Virtual Machine chain on t…8.1
- CVE-2024-39697phonenumber is a library for parsing, formatting and validat…8.6
- CVE-2024-39698electron-updater allows for automatic updates for Electron a…7.5
- CVE-2024-39699Directus is a real-time API and App dashboard for managing S…5
- CVE-2024-3970Server Side Request Forgery vulnerability has been discovere…7.5
Are you affected by CVE-2024-39694?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
