Account Locking Bypass in WSO2 Identity Server
CVE-2024-6832

5.9MEDIUM

What is CVE-2024-6832?

A vulnerability exists in the WSO2 Identity Server where the account locking mechanism fails to activate when secondary user stores are unreachable. This flaw results in an inconsistent state for account locking, allowing attackers to repeatedly attempt authentication using invalid credentials. As a result, users linked to accessible user stores can be subjected to brute force attacks without the anticipated lockout penalties, thereby exposing sensitive information and increasing security risks.

Affected Version(s)

WSO2 API Control Plane 4.5.0 < 4.5.0.40

WSO2 API Control Plane 4.6.0 < 4.6.0.4

WSO2 API Control Plane 4.6.0 < 4.6.0.5

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.