User Input Validation Flaw in WSO2 Products
CVE-2024-10302

4MEDIUM

What is CVE-2024-10302?

A significant input validation flaw exists in multiple WSO2 products during user self-signup processes. This vulnerability permits malicious or improperly formatted data to gain entry into user claims without adequate validation. Consequently, this unvalidated input can lead to various downstream security risks, namely content manipulation, potential redirection attacks, user interface inconsistencies, unauthorized actions, and data exposure. The extent of the impact is contingent on how this compromised data is utilized, as well as the user privileges associated with the affected accounts.

Affected Version(s)

WSO2 API Control Plane 4.5.0 < 4.5.0.10

WSO2 API Manager 3.1.0 < 3.1.0.331

WSO2 API Manager 3.2.0 < 3.2.0.427

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.