Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h94w-8qhg-3xmc

Опубликовано: 05 мая 2025
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

WSO2 API Manager XML External Entity (XXE) vulnerability

An XML External Entity (XXE) vulnerability exists in the gateway component of WSO2 API Manager due to insufficient validation of XML input in crafted URL paths. User-supplied XML is parsed without appropriate restrictions, enabling external entity resolution.

This vulnerability can be exploited by an unauthenticated remote attacker to read files from the server’s filesystem or perform denial-of-service (DoS) attacks.

  • On systems running JDK 7 or early JDK 8, full file contents may be exposed.

  • On later versions of JDK 8 and newer, only the first line of a file may be read, due to improvements in XML parser behavior.

  • DoS attacks such as "Billion Laughs" payloads can cause service disruption.

Пакеты

Наименование

org.wso2.am:am-distribution-parent

maven
Затронутые версииВерсия исправления

< 2.1.0

2.1.0

EPSS

Процентиль: 68%
0.01287
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 9.1
nvd
больше 1 года назад

Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (XXE) resolution in multiple WSO2 Products. A successful XXE attack could allow a remote, unauthenticated attacker to: * Read sensitive files from the server’s filesystem. * Perform denial-of-service (DoS) attacks, which can render the affected service unavailable.

CVSS3: 9.1
fstec
больше 1 года назад

Уязвимость платформы для интеграции интерфейсов прикладного программирования, приложений и веб-служб WSO2, связанная с неверным ограничением XML-ссылок на внешние объекты, позволяющая нарушителю проводить XXE-атаки

EPSS

Процентиль: 68%
0.01287
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-611