Authentication Bypass in WSO2 Products by WSO2
CVE-2024-6541

6.8MEDIUM

What is CVE-2024-6541?

The vulnerability arises from improperly handled messageContext properties in WSO2 products, allowing authenticated users to access or modify data across distinct system invocations. This flaw presents risks of sensitive information leakage and unauthorized data alterations, heavily reliant on how these properties are deployed within the system. The implications vary, but potential exposure of user data and unintentional data integrity breaches are significant concerns that demand immediate attention.

Affected Version(s)

WSO2 API Manager 3.2.0 < 3.2.0.394

WSO2 API Manager 3.2.1 < 3.2.1.21

WSO2 API Manager 4.0.0 < 4.0.0.311

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.