Session Hijacking Vulnerability in WSO2 API Manager and Other Products
CVE-2020-24703

8.8HIGH

Key Information:

Vendor

Wso2

Vendor
CVE Published:
27 August 2020

What is CVE-2020-24703?

An issue was discovered in certain WSO2 products, where a valid Carbon Management Console session cookie may be inadvertently transmitted to an attacker-controlled server. This occurs when a victim submits a crafted 'Try It' request, allowing an attacker to hijack the session. The vulnerability impacts several WSO2 products, potentially exposing sensitive information and compromising the integrity of user sessions.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-24703 : Session Hijacking Vulnerability in WSO2 API Manager and Other Products