CVE-2024-8995

MEDIUMCVSS 4.9/10EPSS 0.12%

Last modified

CVE-2024-8995 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused. If an attacker possesses both the authorization code and the associated client credentials (client ID and client secret), they can leverage these unused codes to obtain access tokens on behalf of users who have already been deleted. EPSS estimates a 0.12% chance of exploitation in the next 30 days.

Description

Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused. If an attacker possesses both the authorization code and the associated client credentials (client ID and client secret), they can leverage these unused codes to obtain access tokens on behalf of users who have already been deleted. This may lead to unauthorized access to sensitive resources and services, contingent on the scopes originally authorized for the compromised authorization code.

Metrics

CVSS 3.1
4.9/10

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N

EPSS Probability
0.12%

2.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Wso2Api Control Plane>= 4.5.0, < 4.5.0.56
Wso2Api Control Plane>= 4.6.0, < 4.6.0.20
Wso2Api Manager>= 3.1.0, < 3.1.0.320
Wso2Api Manager>= 3.2.0, < 3.2.0.413
Wso2Api Manager>= 3.2.1, < 3.2.1.90
Wso2Api Manager>= 4.0.0, < 4.0.0.334
Wso2Api Manager>= 4.1.0, < 4.1.0.255
Wso2Api Manager>= 4.2.0, < 4.2.0.195
Wso2Api Manager>= 4.3.0, < 4.3.0.106
Wso2Api Manager>= 4.4.0, < 4.4.0.70
Wso2Api Manager>= 4.5.0, < 4.5.0.55
Wso2Api Manager>= 4.6.0, < 4.6.0.19
Wso2Identity Server>= 5.10.0, < 5.10.338
Wso2Identity Server>= 5.11.0, < 5.11.0.395
Wso2Identity Server>= 6.0.0, < 6.0.0.229
Wso2Identity Server>= 6.1.0, < 6.1.0.208
Wso2Identity Server As Key Manager>= 5.10.0, < 5.10.0.338
Wso2Open Banking Am>= 2.0.0, < 2.0.0.369
Wso2Open Banking Iam>= 2.0.0, < 2.0.0.389
Wso2Traffic Manager>= 4.5.0, < 4.5.0.54
Wso2Traffic Manager>= 4.6.0, < 4.6.0.19
Wso2Universal Gateway>= 4.5.0, < 4.5.0.55
Wso2Universal Gateway>= 4.6.0, < 4.6.0.19

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2024-8995?
Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused. If an attacker possesses both the authorization code and the associated client credentials (client ID and client secret), they can leverage these unused codes to obtain access tokens on behalf of users who have already been deleted. This may lead to unauthorized access to sensitive resources and services, contingent on the scopes originally authorized for the compromised authorization code.
How severe is CVE-2024-8995?
CVE-2024-8995 has a CVSS score of 4.9/10 (MEDIUM severity). The EPSS model estimates a 0.12% probability of exploitation in the next 30 days.
How do I fix CVE-2024-8995?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2024

Are you affected by CVE-2024-8995?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST