← Back

CVE-2024-2374

nvd nist
Published: Apr 16, 2026Modified: Jun 17, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entities. This omission allows malicious actors to craft XML payloads that exploit the parser's behavior, leading to the inclusion of external resources. By leveraging this vulnerability, an attacker can read confidential files from the file system and access limited HTTP resources reachable by the product. Additionally, the vulnerability can be exploited to perform denial of service attacks by exhausting server resources through recursive entity expansion or fetching large external resources.

Affected (13)

5 products
Api Manager
Identity Server
Identity Server As Key Manager
Open Banking Am
Open Banking Iam
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
From 3.1.0 to 3.1.0.278
From 3.2.0 to 3.2.0.368
From 4.0.0 to 4.0.0.280
From 4.1.0 to 4.1.0.206
From 4.2.0 to 4.2.0.144
From 4.3.0 to 4.3.0.57
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
From 5.10.0 to 5.10.0.300
From 5.11.0 to 5.11.0.329
From 6.0.0 to 6.0.0.179
From 6.1.0 to 6.1.0.136
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
From 5.10.0 to 5.10.0.296
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
From 2.0.0 to 2.0.0.328
From 2.0.0 to 2.0.0.348

References (1)

Timeline

No history available yet.