Information Disclosure Vulnerability in WSO2 Products
CVE-2024-4598
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 23 September 2025
What is CVE-2024-4598?
An information disclosure vulnerability exists across various WSO2 products due to the improper implementation of the enrich mediator. This flaw allows authenticated users to potentially view sensitive business data from other mediation contexts because the internal state is not adequately isolated or cleared during executions. While this vulnerability does not compromise user credentials or access tokens, it raises significant concerns about the inadvertent exposure of sensitive information handled in message flows.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WSO2 API Manager 3.2.0 < 3.2.0.422
WSO2 API Manager 3.2.1 < 3.2.1.42
WSO2 API Manager 4.1.0 < 4.1.0.152
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
