Information Disclosure Vulnerability in WSO2 Products
CVE-2024-4598
6.5MEDIUM
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 23 September 2025
What is CVE-2024-4598?
An information disclosure vulnerability exists across various WSO2 products due to the improper implementation of the enrich mediator. This flaw allows authenticated users to potentially view sensitive business data from other mediation contexts because the internal state is not adequately isolated or cleared during executions. While this vulnerability does not compromise user credentials or access tokens, it raises significant concerns about the inadvertent exposure of sensitive information handled in message flows.
Affected Version(s)
WSO2 API Manager 3.2.0 < 3.2.0.422
WSO2 API Manager 3.2.1 < 3.2.1.42
WSO2 API Manager 4.1.0 < 4.1.0.152