CVE-2024-8010
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
The component accepts XML input through the publisher without disabling external entity resolution. This allows malicious actors to submit a crafted XML payload that exploits the unescaped external entity references.
By leveraging this vulnerability, a malicious actor can read confidential files from the product's file system or access limited HTTP resources reachable via HTTP GET requests to the vulnerable product.
Affected (6)
Products: Wso2: Api Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.2.0 to 3.2.0.397 |
References (1)
Source: ed10eef1-636d-4fbe-9993-6890dfa878f8
Vendor Advisory
Timeline
No history available yet.