WSO2 API Manager是美国WSO2公司开源的一套API生命周期管理解决方案。 WSO2 API Manager存在服务端请求伪造漏洞,该漏洞源于消息流组件在处理WS-Addressing标头时未充分验证用户控制的输入,可能导致未经身份验证的攻击者控制服务器发起请求的目的地,从而造成服务端请求伪造。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| WSO2 | WSO2 API Manager | < 3.1.0 |
unknown |
3.1.0< 3.1.0.360 |
affected | ||
3.2.0< 3.2.0.465 |
affected | ||
3.2.1< 3.2.1.84 |
affected | ||
4.0.0< 4.0.0.385 |
affected | ||
4.2.0< 4.2.0.189 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WSO2 | WSO2 API Manager | 3.1.0 ~ 3.1.0.360 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet