Security Advisory WSO2-2025-3857/CVE-2025-0326

Published: 2025-03-18

Updated: 2025-03-18

Version: 1.0.0

Severity: Medium

CVSS Score: 6.3 (CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N)


AFFECTED PRODUCTS

  • WSO2 Identity Server 7.0.0

OVERVIEW

Already issued access tokens remain active for sub-organization users in certain scenarios.

DESCRIPTION

The system fails to invalidate existing access tokens associated with sub-organization users during the following scenarios: password reset, role change, or sub-organization disablement. Consequently, these tokens remain active.

IMPACT

The identified issue could lead to unauthorized access only if previously issued tokens remain active and the tokens are already exposed to malicious actors.

SOLUTION

Community Users (Open Source)

Apply the relevant fixes to your product using the public fix(es) provided below.

If applying the fix or update is not feasible, migrate to the latest unaffected version of the respective WSO2 product(s).

Support Subscription Holders

Update your product to the specified update level—or a higher update level—to apply the fix.

Info

WSO2 Support Subscription Holders may use WSO2 Updates in order to apply the fix.

Product Version U2 Update Level
WSO2 Identity Server 7.0.0 85