Authorization Flaw in WSO2 Products Allows Direct API Access
CVE-2024-2321

5.6MEDIUM

Key Information:

Vendor

Wso2

Vendor
CVE Published:
27 February 2025

What is CVE-2024-2321?

A vulnerability exists in multiple WSO2 products that allows unauthorized access to secured APIs by exploiting improper authorization checks. This can occur when an attacker utilizes a valid admin user refresh token, bypassing the necessary access token mechanism. As refresh tokens typically maintain longer validity, this misconfiguration can potentially grant enduring access to sensitive API resources, thereby jeopardizing data confidentiality and integrity. For detailed information and mitigation, refer to the vendor's advisory.

Affected Version(s)

WSO2 API Manager 4.0.0 < 4.0.0.275

WSO2 API Manager 4.1.0 < 4.1.0.153

WSO2 API Manager 4.2.0 < 4.2.0.83

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.