CVE-2024-8010
EUVD-2024-5554916.04.2026, 10:16
The component accepts XML input through the publisher without disabling external entity resolution. This allows malicious actors to submit a crafted XML payload that exploits the unescaped external entity references. By leveraging this vulnerability, a malicious actor can read confidential files from the product's file system or access limited HTTP resources reachable via HTTP GET requests to the vulnerable product.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| wso2 | api_manager | 3.2.0 ≤ 𝑥 < 3.2.0.397 |
| wso2 | api_manager | 3.2.1 ≤ 𝑥 < 3.2.1.27 |
| wso2 | api_manager | 4.0.0 ≤ 𝑥 ≤ 4.0.0.310 |
| wso2 | api_manager | 4.1.0 ≤ 𝑥 < 4.1.0.171 |
| wso2 | api_manager | 4.2.0 ≤ 𝑥 < 4.2.0.127 |
| wso2 | api_manager | 4.3.0 ≤ 𝑥 < 4.3.0.39 |
𝑥
= Vulnerable software versions