目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2024-6541— WSO2 多个产品消息上下文处理不当导致信息泄露和完整性破坏漏洞

CVSS 6.8 · Medium

Possible ATT&CK Techniques 1AI

T1135 · Network Share Discovery
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2024-6541の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Information Disclosure and Integrity Violation via Improper Message Context Handling in Multiple WSO2 Products
ソース: CVE Program / CVE List V5
脆弱性説明
The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated. This weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. The exact impact depends on how `messageContext` properties are utilized within the affected WSO2 products.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
ソース: CVE Program / CVE List V5
脆弱性タイプ
输入验证不恰当
ソース: CVE Program / CVE List V5

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
WSO2WSO2 Micro Integrator 1.2.0 ~ 1.2.0.163 -
WSO2WSO2 Enterprise Integrator 6.6.0 ~ 6.6.0.205 -
WSO2WSO2 API Manager 3.2.0 ~ 3.2.0.394 -
WSO2WSO2-Synapse 2.1.7.wso2v182 ~ 2.1.7.wso2v182_93 -

II. CVE-2024-6541の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2024-6541のインテリジェンス情報

登录查看更多情报信息。

CVE-2024-6541 厂商安全公告 (1)

Same Patch Batch · WSO2 · 2026-08-06 · 19 CVEs total

CVE-2026-543010.0 CRITICALAuthentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account
CVE-2026-17289.8 CRITICALPrivilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account
CVE-2025-150399.4 CRITICALAccount Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products
CVE-2026-34189.1 CRITICALArbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Exe
CVE-2025-145619.0 CRITICALAccess Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenan
CVE-2026-34158.7 HIGHXML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows
CVE-2024-68325.9 MEDIUMAccount Lockout Failure via Secondary User Store Inaccessibility in Multiple WSO2 Products
CVE-2025-133945.4 MEDIUMCross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables
CVE-2025-123175.0 MEDIUMImproper Token Revocation via SOAP Services in Multiple WSO2 Products Allows Retained Acce
CVE-2024-89954.9 MEDIUMAuthorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthor
CVE-2026-06374.4 MEDIUMSensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products
CVE-2025-139094.3 MEDIUMInformation Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allow
CVE-2025-118504.3 MEDIUMImproper Implicit Association via User Store Initialization in WSO2 Identity Server [Ident
CVE-2025-65084.3 MEDIUMUser Interface Misrepresentation via Swagger UI Try-out Console in WSO2 API Manager Allows
CVE-2024-103024.0 MEDIUMImproper Input Validation via Signup Process in Multiple WSO2 Products Enables Content Man
CVE-2025-147793.8 LOWImproper Access Control via Secret Type Management API in WSO2 Identity Server
CVE-2025-137363.7 LOWUsername Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Dis
CVE-2025-126272.4 LOWImproper Refresh Token Implementation via User Impersonation Flow in WSO2 Identity Server

IV. 関連脆弱性

V. CVE-2024-6541へのコメント

まだコメントはありません


コメントを残す