Vulnerability in WSO2 Product Affecting Authorization Code Management
CVE-2024-8995

4.9MEDIUM

What is CVE-2024-8995?

The vulnerability pertains to the failure of the WSO2 Identity Server to adequately invalidate authorization codes linked to deleted users. When a user account is deleted, any associated authorization codes should be removed from the system to prevent unauthorized access. However, these codes remain valid, allowing attackers with the right client credentials to misuse them for obtaining access tokens. This potentially compromises sensitive user data by enabling unauthorized access to resources that are no longer meant to be accessible.

Affected Version(s)

WSO2 API Control Plane 4.5.0 < 4.5.0.56

WSO2 API Control Plane 4.6.0 < 4.6.0.20

WSO2 API Manager 3.1.0 < 3.1.0.320

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.