Security Advisory WSO2-2024-3520/CVE-2024-6541

Published: 2026-05-03

Version: 1.0.0

Severity: Medium

CVSS Score: 6.8 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N)

CVE IDs: CVE-2024-6541


AFFECTED PRODUCTS

  • WSO2 API Manager: 4.3.0, 4.2.0, 4.1.0, 4.0.0, 3.2.1, 3.2.0
  • WSO2 Enterprise Integrator: 6.6.0
  • WSO2 Micro Integrator: 4.3.0, 4.1.0, 1.2.0

OVERVIEW

Potential information disclosure and integrity violation.

DESCRIPTION

Due to the improper implementation of Class Mediator authenticated users of the system may see data across invocations or may be able to perform unintended modification when messageContext properties are used for dynamic values.

IMPACT

This vulnerability can expose certain business information across invocations or may be used to perform unintended modifications to request data. However, it does not impact user credentials or access tokens. The vulnerability occurs only when Class Mediator is used and messageContext properties are used for dynamic value string operations, even though this is discouraged in the product documentation 1.

SOLUTION

Community Users (Open Source)

Apply the relevant fixes to your product using the public fix(es) provided below.

If applying the fix or update is not feasible, migrate to the latest unaffected version of the respective WSO2 product(s).

Support Subscription Holders

Update your product to the specified update level, or to a higher update level, to mitigate the identified vulnerability.

Info

WSO2 Support Subscription Holders may use WSO2 Updates in order to apply the fix.

Product Name Product Version Update Level
WSO2 API Manager 4.3.0 24
WSO2 API Manager 4.2.0 110
WSO2 API Manager 4.1.0 167
WSO2 API Manager 4.0.0 311
WSO2 API Manager 3.2.1 21
WSO2 API Manager 3.2.0 394
WSO2 Enterprise Integrator 6.6.0 205
WSO2 Micro Integrator 4.3.0 7
WSO2 Micro Integrator 4.1.0 103
WSO2 Micro Integrator 1.2.0 163

REFERENCES