CVE-2024-8995

Summary

Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused.

If an attacker possesses both the authorization code and the associated client credentials (client ID and client secret), they can leverage these unused codes to obtain access tokens on behalf of users who have already been deleted. This may lead to unauthorized access to sensitive resources and services, contingent on the scopes originally authorized for the compromised authorization code.

Affected Software

VendorProductVersion RangeStatus
WSO2WSO2 API Manager0 < 3.1.0unknown
WSO2WSO2 API Manager3.1.0 < 3.1.0.320affected
WSO2WSO2 API Manager3.2.0 < 3.2.0.413affected
WSO2WSO2 API Manager3.2.1 < 3.2.1.90affected
WSO2WSO2 API Manager4.0.0 < 4.0.0.334affected
WSO2WSO2 API Manager4.1.0 < 4.1.0.255affected
WSO2WSO2 API Manager4.2.0 < 4.2.0.195affected
WSO2WSO2 API Manager4.3.0 < 4.3.0.106affected
WSO2WSO2 API Manager4.4.0 < 4.4.0.70affected
WSO2WSO2 API Manager4.5.0 < 4.5.0.55affected
WSO2WSO2 API Manager4.6.0 < 4.6.0.19affected
WSO2WSO2 Traffic Manager4.5.0 < 4.5.0.54affected
WSO2WSO2 Traffic Manager4.6.0 < 4.6.0.19affected
WSO2WSO2 API Control Plane4.5.0 < 4.5.0.56affected
WSO2WSO2 API Control Plane4.6.0 < 4.6.0.20affected
WSO2WSO2 Universal Gateway4.5.0 < 4.5.0.55affected
WSO2WSO2 Universal Gateway4.6.0 < 4.6.0.19affected
WSO2WSO2 Open Banking AM0 < 2.0.0unknown
WSO2WSO2 Open Banking AM2.0.0 < 2.0.0.369affected
WSO2WSO2 Identity Server0 < 5.10.0unknown
WSO2WSO2 Identity Server5.10.0 < 5.10.0.345affected
WSO2WSO2 Identity Server5.11.0 < 5.11.0.395affected
WSO2WSO2 Identity Server6.0.0 < 6.0.0.229affected
WSO2WSO2 Identity Server6.1.0 < 6.1.0.208affected
WSO2WSO2 Open Banking IAM0 < 2.0.0unknown
WSO2WSO2 Open Banking IAM2.0.0 < 2.0.0.389affected
WSO2WSO2 Identity Server as Key Manager0 < 5.10.0unknown
WSO2WSO2 Identity Server as Key Manager5.10.0 < 5.10.0.338affected
WSO2WSO2 Carbon OAuth6.4.2 < 6.4.2.154affected
WSO2WSO2 Carbon OAuth6.4.111 < 6.4.111.131affected
WSO2WSO2 Carbon OAuth6.4.176 < 6.4.176.35affected
WSO2WSO2 Carbon OAuth6.4.180 < 6.4.180.17affected
WSO2WSO2 Carbon OAuth6.8.0 < 6.8.0.46affected
WSO2WSO2 Carbon OAuth6.9.6 < 6.9.6.34affected
WSO2WSO2 Carbon OAuth6.11.21 < 6.11.21.59affected
WSO2WSO2 Carbon OAuth6.13.16 < 6.13.16.27affected
WSO2WSO2 Carbon OAuth6.13.19 < 6.13.19.19affected
WSO2WSO2 Carbon OAuth6.13.27 < 6.13.27.15affected
WSO2WSO2 Carbon OAuth6.13.41 < 6.13.41.4affected
WSO2WSO2 Carbon OAuth6.11.53 <= *unaffected

Weaknesses

  • CWE-613: CWE-613: Insufficient Session Expiration

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References