CVE-2023-6837

HIGHCVSS 8.2/10EPSS 0.46%

Last modified

CVE-2023-6837 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to have any impact on your deployment, following conditions must be met: * An IDP configured for federated authentication and JIT provisioning enabled with the "Prompt for username, password and consent" option. * A service provider that uses the above IDP for federated authentication and has the "Assert identity using mapped local subject identifier" flag enabled. Attacker should have: * A fresh valid user account in the federated IDP that has not been used earlier. * Knowledge of the username of a valid user in the local IDP. When all preconditions are met, a malicious actor could use JIT provisioning flow to perform user impersonation.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.

Description

Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to have any impact on your deployment, following conditions must be met: * An IDP configured for federated authentication and JIT provisioning enabled with the "Prompt for username, password and consent" option. * A service provider that uses the above IDP for federated authentication and has the "Assert identity using mapped local subject identifier" flag enabled. Attacker should have: * A fresh valid user account in the federated IDP that has not been used earlier. * Knowledge of the username of a valid user in the local IDP. When all preconditions are met, a malicious actor could use JIT provisioning flow to perform user impersonation.

Metrics

CVSS 3.1
8.2/10

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

EPSS Probability
0.46%

36.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Wso2Api Manager>= 2.5.0, < 2.5.0.32
Wso2Api Manager>= 2.6.0, < 2.6.0.52
Wso2Api Manager>= 3.0.0, < 3.0.0.50
Wso2Api Manager>= 3.1.0, < 3.1.0.72
Wso2Api Manager>= 3.2.0, < 3.2.0.86
Wso2Api Manager>= 4.0.0, < 4.0.0.35
Wso2Identity Server>= 5.6.0, < 5.6.0.16
Wso2Identity Server>= 5.7.0, < 5.7.0.35
Wso2Identity Server>= 5.8.0, < 5.8.0.26
Wso2Identity Server>= 5.9.0, < 5.9.0.38
Wso2Identity Server>= 5.10.0, < 5.10.0.78
Wso2Identity Server>= 5.11.0, < 5.11.0.69
Wso2Identity Server As Key Manager>= 5.6.0, < 5.6.0.17
Wso2Identity Server As Key Manager>= 5.7.0, < 5.7.0.39
Wso2Identity Server As Key Manager>= 5.9.0, < 5.9.0.45
Wso2Identity Server As Key Manager>= 5.10.0, < 5.10.0.80
Wso2Carbon Identity Application Authentication Endpoint< 5.11.256.3
Wso2Carbon Identity Application Authentication Endpoint>= 5.11.257.0, < 5.12.153.19
Wso2Carbon Identity Application Authentication Endpoint>= 5.12.154.0, < 5.20.254
Wso2Carbon Identity Application Authentication Framework< 5.11.256.3
Wso2Carbon Identity Application Authentication Framework>= 5.11.257.0, < 5.12.153.21
Wso2Carbon Identity Application Authentication Framework>= 5.12.154.0, < 5.12.387.7
Wso2Carbon Identity Application Authentication Framework>= 5.12.388.0, < 5.14.97.22
Wso2Carbon Identity Application Authentication Framework>= 5.14.98.0, < 5.17.5.106
Wso2Carbon Identity Application Authentication Framework>= 5.17.6.0, < 5.18.187.76
Wso2Carbon Identity Application Authentication Framework>= 5.18.188.0, < 5.20.254

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-6837?
Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to have any impact on your deployment, following conditions must be met: * An IDP configured for federated authentication and JIT provisioning enabled with the "Prompt for username, password and consent" option. * A service provider that uses the above IDP for federated authentication and has the "Assert identity using mapped local subject identifier" flag enabled. Attacker should have: * A fresh valid user account in the federated IDP that has not been used earlier. * Knowledge of the username of a valid user in the local IDP. When all preconditions are met, a malicious actor could use JIT provisioning flow to perform user impersonation.
How severe is CVE-2023-6837?
CVE-2023-6837 has a CVSS score of 8.2/10 (HIGH severity). The EPSS model estimates a 0.46% probability of exploitation in the next 30 days.
How do I fix CVE-2023-6837?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-6837?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST