CVE-2024-3511
Incorrect Authorization in Multiple WSO2 Products Allows Unauthorized Access to Registry Versioned Files
Severity Score
4.3
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, a malicious actor with access to the management console can exploit a specific bypass method to retrieve versioned files without proper authorization. Successful exploitation of this vulnerability could lead to unauthorized disclosure of configuration or resource files that may be stored as registry versions, potentially aiding further attacks or system reconnaissance.
*Credits:
Viral Maniar - Security Researcher at Preemptive Cyber Security Pty Ltd
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-04-09 CVE Reserved
- 2025-06-23 CVE Published
- 2025-06-23 CVE Updated
- 2025-06-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-863: Incorrect Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
WSO2 Search vendor "WSO2" | WSO2 Enterprise Integrator Search vendor "WSO2" for product "WSO2 Enterprise Integrator" | >= 6.6.0.0 < 6.6.0.205 Search vendor "WSO2" for product "WSO2 Enterprise Integrator" and version " >= 6.6.0.0 < 6.6.0.205" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 API Manager Search vendor "WSO2" for product "WSO2 API Manager" | >= 3.1.0.0 < 3.1.0.273 Search vendor "WSO2" for product "WSO2 API Manager" and version " >= 3.1.0.0 < 3.1.0.273" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 API Manager Search vendor "WSO2" for product "WSO2 API Manager" | >= 3.2.0.0 < 3.2.0.361 Search vendor "WSO2" for product "WSO2 API Manager" and version " >= 3.2.0.0 < 3.2.0.361" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 API Manager Search vendor "WSO2" for product "WSO2 API Manager" | >= 3.2.1.0 < 3.2.1.13 Search vendor "WSO2" for product "WSO2 API Manager" and version " >= 3.2.1.0 < 3.2.1.13" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 API Manager Search vendor "WSO2" for product "WSO2 API Manager" | >= 4.0.0.0 < 4.0.0.306 Search vendor "WSO2" for product "WSO2 API Manager" and version " >= 4.0.0.0 < 4.0.0.306" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 API Manager Search vendor "WSO2" for product "WSO2 API Manager" | >= 4.1.0.0 < 4.1.0.163 Search vendor "WSO2" for product "WSO2 API Manager" and version " >= 4.1.0.0 < 4.1.0.163" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 API Manager Search vendor "WSO2" for product "WSO2 API Manager" | >= 4.2.0.0 < 4.2.0.98 Search vendor "WSO2" for product "WSO2 API Manager" and version " >= 4.2.0.0 < 4.2.0.98" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 API Manager Search vendor "WSO2" for product "WSO2 API Manager" | >= 4.3.0.0 < 4.3.0.17 Search vendor "WSO2" for product "WSO2 API Manager" and version " >= 4.3.0.0 < 4.3.0.17" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 Identity Server As Key Manager Search vendor "WSO2" for product "WSO2 Identity Server As Key Manager" | >= 5.10.0.0 < 5.10.0.289 Search vendor "WSO2" for product "WSO2 Identity Server As Key Manager" and version " >= 5.10.0.0 < 5.10.0.289" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 Identity Server Search vendor "WSO2" for product "WSO2 Identity Server" | >= 5.10.0.0 < 5.10.0.292 Search vendor "WSO2" for product "WSO2 Identity Server" and version " >= 5.10.0.0 < 5.10.0.292" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 Identity Server Search vendor "WSO2" for product "WSO2 Identity Server" | >= 5.11.0.0 < 5.11.0.333 Search vendor "WSO2" for product "WSO2 Identity Server" and version " >= 5.11.0.0 < 5.11.0.333" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 Identity Server Search vendor "WSO2" for product "WSO2 Identity Server" | >= 6.0.0.0 < 6.0.0.180 Search vendor "WSO2" for product "WSO2 Identity Server" and version " >= 6.0.0.0 < 6.0.0.180" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 Identity Server Search vendor "WSO2" for product "WSO2 Identity Server" | >= 6.1.0.0 < 6.1.0.141 Search vendor "WSO2" for product "WSO2 Identity Server" and version " >= 6.1.0.0 < 6.1.0.141" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 Identity Server Search vendor "WSO2" for product "WSO2 Identity Server" | >= 7.0.0.0 < 7.0.0.8 Search vendor "WSO2" for product "WSO2 Identity Server" and version " >= 7.0.0.0 < 7.0.0.8" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 Open Banking AM Search vendor "WSO2" for product "WSO2 Open Banking AM" | >= 2.0.0.0 < 2.0.0.320 Search vendor "WSO2" for product "WSO2 Open Banking AM" and version " >= 2.0.0.0 < 2.0.0.320" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 Open Banking IAM Search vendor "WSO2" for product "WSO2 Open Banking IAM" | >= 2.0.0.0 < 2.0.0.341 Search vendor "WSO2" for product "WSO2 Open Banking IAM" and version " >= 2.0.0.0 < 2.0.0.341" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 Carbon User Manager Kernel Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" | >= 4.5.0.0 < 4.5.0.5 Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" and version " >= 4.5.0.0 < 4.5.0.5" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 Carbon User Manager Kernel Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" | >= 4.5.3.0 < 4.5.3.35 Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" and version " >= 4.5.3.0 < 4.5.3.35" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 Carbon User Manager Kernel Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" | >= 4.6.0.0 < 4.6.0.140 Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" and version " >= 4.6.0.0 < 4.6.0.140" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 Carbon User Manager Kernel Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" | >= 4.6.1.0 < 4.6.1.107 Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" and version " >= 4.6.1.0 < 4.6.1.107" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 Carbon User Manager Kernel Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" | >= 4.6.2.0 < 4.6.2.323 Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" and version " >= 4.6.2.0 < 4.6.2.323" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 Carbon User Manager Kernel Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" | >= 4.6.3.0 < 4.6.3.18 Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" and version " >= 4.6.3.0 < 4.6.3.18" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 Carbon User Manager Kernel Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" | >= 4.6.4.0 < 4.6.4.3 Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" and version " >= 4.6.4.0 < 4.6.4.3" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 Carbon User Manager Kernel Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" | >= 4.7.1.0 < 4.7.1.47 Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" and version " >= 4.7.1.0 < 4.7.1.47" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 Carbon User Manager Kernel Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" | >= 4.8.1.0 < 4.8.1.19 Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" and version " >= 4.8.1.0 < 4.8.1.19" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 Carbon User Manager Kernel Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" | >= 4.9.0.0 < 4.9.0.52 Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" and version " >= 4.9.0.0 < 4.9.0.52" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 Carbon User Manager Kernel Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" | >= 4.9.26.0 < 4.9.26.10 Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" and version " >= 4.9.26.0 < 4.9.26.10" | en |
Affected
| ||||||
WSO2 Search vendor "WSO2" | WSO2 Carbon User Manager Kernel Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" | >= 4.10.9.0 < 4.10.9.8 Search vendor "WSO2" for product "WSO2 Carbon User Manager Kernel" and version " >= 4.10.9.0 < 4.10.9.8" | en |
Affected
|