CVE-2024-39694 - CVE House
Back to Database
Status published Medium CVE-2024-39694

Duende IdentityServer Open Redirect vulnerability

Vulnerability Description

Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to craft malicious Urls that certain functions in IdentityServer will incorrectly treat as local and trusted. If such a Url is returned as a redirect, some browsers will follow it to a third-party, untrusted site. Note: by itself, this vulnerability does **not** allow an attacker to obtain user credentials, authorization codes, access tokens, refresh tokens, or identity tokens. An attacker could however exploit this vulnerability as part of a phishing attack designed to steal user credentials. This vulnerability is fixed in 7.0.6, 6.3.10, 6.2.5, 6.1.8, and 6.0.5. Duende.IdentityServer 5.1 and earlier and all versions of IdentityServer4 are no longer supported and will not be receiving updates. If upgrading is not possible, use `IUrlHelper.IsLocalUrl` from ASP.NET Core to validate return Urls in user interface code in the IdentityServer host.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-39694

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

DuendeSoftware

View all reports →

Affected Software

IdentityServer
Vulnerable Versions:
< 6.0.5, >= 6.1.0-preview.1, <= 6.1.7, >= 6.2.0-preview.1, <= 6.2.4, >= 6.3.0-preview.1, <= 6.3.9, >= 7.0.0-preview.1, <= 7.0.5

Timeline

Official Publish: July 31st, 2024
Last Modified: July 31st, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

Weaknesses (CWE)