CVE-2024-8995

EUVD-2024-55706
Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused.

If an attacker possesses both the authorization code and the associated client credentials (client ID and client secret), they can leverage these unused codes to obtain access tokens on behalf of users who have already been deleted. This may lead to unauthorized access to sensitive resources and services, contingent on the scopes originally authorized for the compromised authorization code.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.9 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 2.04%
Affected Products (NVD)
VendorProductVersion
wso2api_control_plane
4.5.0 ≤
𝑥
< 4.5.0.56
wso2api_control_plane
4.6.0 ≤
𝑥
< 4.6.0.20
wso2api_manager
3.1.0 ≤
𝑥
< 3.1.0.320
wso2api_manager
3.2.0 ≤
𝑥
< 3.2.0.413
wso2api_manager
3.2.1 ≤
𝑥
< 3.2.1.90
wso2api_manager
4.0.0 ≤
𝑥
< 4.0.0.334
wso2api_manager
4.1.0 ≤
𝑥
< 4.1.0.255
wso2api_manager
4.2.0 ≤
𝑥
< 4.2.0.195
wso2api_manager
4.3.0 ≤
𝑥
< 4.3.0.106
wso2api_manager
4.4.0 ≤
𝑥
< 4.4.0.70
wso2api_manager
4.5.0 ≤
𝑥
< 4.5.0.55
wso2api_manager
4.6.0 ≤
𝑥
< 4.6.0.19
wso2identity_server
5.10.0 ≤
𝑥
< 5.10.0.338
wso2identity_server
5.11.0 ≤
𝑥
< 5.11.0.395
wso2identity_server
6.0.0 ≤
𝑥
< 6.0.0.229
wso2identity_server
6.1.0 ≤
𝑥
< 6.1.0.208
wso2identity_server_as_key_manager
5.10.0 ≤
𝑥
< 5.10.0.338
wso2open_banking_am
2.0.0 ≤
𝑥
< 2.0.0.369
wso2open_banking_iam
2.0.0 ≤
𝑥
< 2.0.0.389
wso2traffic_manager
4.5.0 ≤
𝑥
< 4.5.0.54
wso2traffic_manager
4.6.0 ≤
𝑥
< 4.6.0.19
wso2universal_gateway
4.5.0 ≤
𝑥
< 4.5.0.55
wso2universal_gateway
4.6.0 ≤
𝑥
< 4.6.0.19
𝑥
= Vulnerable software versions