CVE-2024-6541

Summary

The Class Mediator fails to correctly validate or sanitize messageContext properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated.

This weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. The exact impact depends on how messageContext properties are utilized within the affected WSO2 products.

Affected Software

VendorProductVersion RangeStatus
WSO2WSO2 Micro Integrator0 < 1.2.0unknown
WSO2WSO2 Micro Integrator1.2.0 < 1.2.0.163affected
WSO2WSO2 Micro Integrator4.1.0 < 4.1.0.103affected
WSO2WSO2 Micro Integrator4.3.0 < 4.3.0.7affected
WSO2WSO2 Enterprise Integrator0 < 6.6.0unknown
WSO2WSO2 Enterprise Integrator6.6.0 < 6.6.0.205affected
WSO2WSO2 API Manager0 < 3.2.0unknown
WSO2WSO2 API Manager3.2.0 < 3.2.0.394affected
WSO2WSO2 API Manager3.2.1 < 3.2.1.21affected
WSO2WSO2 API Manager4.0.0 < 4.0.0.311affected
WSO2WSO2 API Manager4.1.0 < 4.1.0.167affected
WSO2WSO2 API Manager4.2.0 < 4.2.0.110affected
WSO2WSO2 API Manager4.3.0 < 4.3.0.24affected
WSO2WSO2-Synapse2.1.7.wso2v182 < 2.1.7.wso2v182_93affected
WSO2WSO2-Synapse2.1.7.wso2v143 < 2.1.7.wso2v143_119affected
WSO2WSO2-Synapse2.1.7.wso2v183 < 2.1.7.wso2v183_62affected
WSO2WSO2-Synapse2.1.7.wso2v319 < 2.1.7.wso2v319_7affected
WSO2WSO2-Synapse2.1.7.wso2v227 < 2.1.7.wso2v227_88affected
WSO2WSO2-Synapse2.1.7.wso2v271 < 2.1.7.wso2v271_60affected
WSO2WSO2-Synapse4.0.0.wso2v119 < 4.0.0.wso2v119_3affected
WSO2WSO2-Synapse4.0.0.wso2v105 < 4.0.0.wso2v105_3affected
WSO2WSO2-Synapse4.0.0.wso2v20 < 4.0.0.wso2v20_63affected
WSO2WSO2-Synapsev4.0.0-wso2v121 <= v4.0.0-wso2v*unaffected

Weaknesses

  • CWE-20: CWE-20: Improper Input Validation

References