Authorization Flaw in WSO2 Products Allows Direct API Access
CVE-2024-2321
5.6MEDIUM
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 27 February 2025
What is CVE-2024-2321?
A vulnerability exists in multiple WSO2 products that allows unauthorized access to secured APIs by exploiting improper authorization checks. This can occur when an attacker utilizes a valid admin user refresh token, bypassing the necessary access token mechanism. As refresh tokens typically maintain longer validity, this misconfiguration can potentially grant enduring access to sensitive API resources, thereby jeopardizing data confidentiality and integrity. For detailed information and mitigation, refer to the vendor's advisory.
Affected Version(s)
WSO2 API Manager 4.0.0 < 4.0.0.275
WSO2 API Manager 4.1.0 < 4.1.0.153
WSO2 API Manager 4.2.0 < 4.2.0.83