CVE-2024-6541

MEDIUMCVSS 6.8/10EPSS 0.26%

Last modified

CVE-2024-6541 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated. This weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. EPSS estimates a 0.26% chance of exploitation in the next 30 days.

Description

The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated. This weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. The exact impact depends on how `messageContext` properties are utilized within the affected WSO2 products.

Metrics

CVSS 3.1
6.8/10

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS Probability
0.26%

17.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
WSO2WSO2 Micro Integrator< 1.2.0; >= 1.2.0, < 1.2.0.163; >= 4.1.0, < 4.1.0.103; >= 4.3.0, < 4.3.0.7
WSO2WSO2 Enterprise Integrator< 6.6.0; >= 6.6.0, < 6.6.0.205
WSO2WSO2 API Manager< 3.2.0; >= 3.2.0, < 3.2.0.394; >= 3.2.1, < 3.2.1.21; >= 4.0.0, < 4.0.0.311; >= 4.1.0, < 4.1.0.167; >= 4.2.0, < 4.2.0.110; >= 4.3.0, < 4.3.0.24
WSO2WSO2-Synapse>= 2.1.7.wso2v182, < 2.1.7.wso2v182_93; >= 2.1.7.wso2v143, < 2.1.7.wso2v143_119; >= 2.1.7.wso2v183, < 2.1.7.wso2v183_62; >= 2.1.7.wso2v319, < 2.1.7.wso2v319_7; >= 2.1.7.wso2v227, < 2.1.7.wso2v227_88; >= 2.1.7.wso2v271, < 2.1.7.wso2v271_60; >= 4.0.0.wso2v119, < 4.0.0.wso2v119_3; >= 4.0.0.wso2v105, < 4.0.0.wso2v105_3; >= 4.0.0.wso2v20, < 4.0.0.wso2v20_63

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2024-6541?
The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated. This weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. The exact impact depends on how `messageContext` properties are utilized within the affected WSO2 products.
How severe is CVE-2024-6541?
CVE-2024-6541 has a CVSS score of 6.8/10 (MEDIUM severity). The EPSS model estimates a 0.26% probability of exploitation in the next 30 days.
How do I fix CVE-2024-6541?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2024

Are you affected by CVE-2024-6541?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST