CVE-2024-3511

Source
https://cve.org/CVERecord?id=CVE-2024-3511
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-3511.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-3511
Published
2025-06-23T09:15:21.580Z
Modified
2026-07-08T07:08:21.538877186Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, a malicious actor with access to the management console can exploit a specific bypass method to retrieve versioned files without proper authorization.

Successful exploitation of this vulnerability could lead to unauthorized disclosure of configuration or resource files that may be stored as registry versions, potentially aiding further attacks or system reconnaissance.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "3.2.1"
                },
                {
                    "last_affected": "3.2.1"
                }
            ],
            "cpes": [
                "cpe:2.3:a:wso2:api_manager:3.2.1:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING",
            "vendor_product": "wso2:api_manager"
        },
        {
            "extracted_events": [
                {
                    "introduced": "5.10.0"
                },
                {
                    "last_affected": "5.10.0"
                },
                {
                    "introduced": "5.11.0"
                },
                {
                    "last_affected": "5.11.0"
                },
                {
                    "introduced": "6.0.0"
                },
                {
                    "last_affected": "6.0.0"
                },
                {
                    "introduced": "6.1.0"
                },
                {
                    "last_affected": "6.1.0"
                },
                {
                    "introduced": "7.0.0"
                },
                {
                    "last_affected": "7.0.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:wso2:identity_server:5.10.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:wso2:identity_server:5.11.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:wso2:identity_server:6.0.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:wso2:identity_server:6.1.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:wso2:identity_server:7.0.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING",
            "vendor_product": "wso2:identity_server"
        },
        {
            "extracted_events": [
                {
                    "introduced": "5.10.0"
                },
                {
                    "last_affected": "5.10.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:wso2:identity_server_as_key_manager:5.10.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING",
            "vendor_product": "wso2:identity_server_as_key_manager"
        },
        {
            "extracted_events": [
                {
                    "introduced": "2.0.0"
                },
                {
                    "last_affected": "2.0.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:wso2:open_banking_am:2.0.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING",
            "vendor_product": "wso2:open_banking_am"
        },
        {
            "extracted_events": [
                {
                    "introduced": "2.0.0"
                },
                {
                    "last_affected": "2.0.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:wso2:open_banking_iam:2.0.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING",
            "vendor_product": "wso2:open_banking_iam"
        }
    ]
}
References

Affected packages

Git / github.com/wso2/product-apim

Affected ranges

Type
GIT
Repo
https://github.com/wso2/product-apim
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "3.2.0"
        },
        {
            "last_affected": "3.2.0"
        },
        {
            "introduced": "4.0.0"
        },
        {
            "last_affected": "4.0.0"
        },
        {
            "introduced": "4.1.0-NA"
        },
        {
            "last_affected": "4.1.0-NA"
        },
        {
            "introduced": "4.2.0-NA"
        },
        {
            "last_affected": "4.2.0-NA"
        },
        {
            "introduced": "4.3.0-NA"
        },
        {
            "last_affected": "4.3.0-NA"
        }
    ],
    "cpe": [
        "cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:wso2:api_manager:4.0.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:wso2:api_manager:4.1.0:-:*:*:*:*:*:*",
        "cpe:2.3:a:wso2:api_manager:4.2.0:-:*:*:*:*:*:*",
        "cpe:2.3:a:wso2:api_manager:4.3.0:-:*:*:*:*:*:*"
    ],
    "source": "CPE_STRING"
}

Affected versions

3.*
3.2.0
4.*
4.0.0
4.0.0-beta
4.1.0-NA
4.2.0-NA
4.3.0-NA
v3.*
v3.2.0
v3.2.0-rc6
v4.*
v4.0.0
v4.0.0-alpha
v4.0.0-beta
v4.0.0-m1
v4.0.0-m2
v4.0.0-m3
v4.0.0-m4
v4.0.0-m5
v4.0.0-m6
v4.0.0-m7
v4.0.0-m8
v4.0.0-rc
v4.1.0
v4.1.0-alpha
v4.1.0-beta
v4.1.0-m1
v4.1.0-m2
v4.1.0-m3
v4.1.0-m4
v4.1.0-rc
v4.1.0-rc2
v4.1.0-rc3
v4.2.0
v4.2.0-alpha
v4.2.0-beta
v4.2.0-m1
v4.2.0-rc
v4.2.0-rc2
v4.3.0
v4.3.0-alpha
v4.3.0-alpha2
v4.3.0-beta
v4.3.0-m2
v4.3.0-rc
v4.3.0-rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-3511.json"

Git / github.com/wso2/product-ei

Affected ranges

Type
GIT
Repo
https://github.com/wso2/product-ei
Events
Database specific
{
    "cpe": "cpe:2.3:a:wso2:enterprise_integrator:6.6.0:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "6.6.0"
        },
        {
            "last_affected": "6.6.0"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

6.*
6.6.0
v6.*
v6.6.0
v6.6.0-rc3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-3511.json"