CVE-2024-2374

EUVD-2024-27327
The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entities. This omission allows malicious actors to craft XML payloads that exploit the parser's behavior, leading to the inclusion of external resources.

By leveraging this vulnerability, an attacker can read confidential files from the file system and access limited HTTP resources reachable by the product. Additionally, the vulnerability can be exploited to perform denial of service attacks by exhausting server resources through recursive entity expansion or fetching large external resources.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
Affected Products (NVD)
VendorProductVersion
wso2api_manager
3.1.0 ≤
𝑥
< 3.1.0.278
wso2api_manager
3.2.0 ≤
𝑥
< 3.2.0.368
wso2api_manager
4.0.0 ≤
𝑥
< 4.0.0.280
wso2api_manager
4.1.0 ≤
𝑥
< 4.1.0.206
wso2api_manager
4.2.0 ≤
𝑥
< 4.2.0.144
wso2api_manager
4.3.0 ≤
𝑥
< 4.3.0.57
wso2identity_server
5.10.0 ≤
𝑥
< 5.10.0.300
wso2identity_server
5.11.0 ≤
𝑥
< 5.11.0.329
wso2identity_server
6.0.0 ≤
𝑥
< 6.0.0.179
wso2identity_server
6.1.0 ≤
𝑥
< 6.1.0.136
wso2identity_server_as_key_manager
5.10.0 ≤
𝑥
< 5.10.0.296
wso2open_banking_am
2.0.0 ≤
𝑥
< 2.0.0.328
wso2open_banking_iam
2.0.0 ≤
𝑥
< 2.0.0.348
𝑥
= Vulnerable software versions