CVE-2024-25566: Open Redirect in PingAM
An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25566?
CVE-2024-25566 is classified as a moderate severity vulnerability due to its potential to facilitate phishing attacks through open redirects.
How do I fix CVE-2024-25566?
To fix CVE-2024-25566, ensure that all redirect URLs are properly validated to prevent unauthorized redirects to malicious sites.
What software versions are affected by CVE-2024-25566?
CVE-2024-25566 affects various versions of ForgeRock Access Management, specifically versions up to 7.0.2 and from 7.1.0 to 7.1.4, 7.2.0 to 7.2.2, and certain versions including 7.3.0 to 7.5.0.
Can CVE-2024-25566 lead to data breaches?
Yes, CVE-2024-25566 could potentially lead to data breaches since it allows attackers to redirect users to sites designed to capture sensitive information.
What types of attacks can CVE-2024-25566 facilitate?
CVE-2024-25566 can facilitate phishing attacks by allowing attackers to redirect users to malicious websites designed to harvest credentials or other sensitive data.