← Back

CVE-2024-3511

nvd nist
Published: Jun 23, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: ed10eef1-636d-4fbe-9993-6890dfa878f8 (Secondary)

Description

An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, a malicious actor with access to the management console can exploit a specific bypass method to retrieve versioned files without proper authorization. Successful exploitation of this vulnerability could lead to unauthorized disclosure of configuration or resource files that may be stored as registry versions, potentially aiding further attacks or system reconnaissance.

Affected (15)

6 products
Api Manager
Enterprise Integrator
Identity Server
Identity Server As Key Manager
Open Banking Am
Open Banking Iam
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
Version 3.2.0
Version 3.2.1
Version 4.0.0
Version 4.1.0
Version 4.2.0
Version 4.3.0
Version 6.6.0
Wso2
Version 5.10.0
Version 5.11.0
Version 6.0.0
Version 6.1.0
Version 7.0.0
Version 5.10.0
Version 2.0.0
Version 2.0.0

References (1)

Timeline

No history available yet.