CVE-2020-13226

CRITICAL

WSO2 API Manager 3.0.0 - Server-Side Request Forgery via Publisher Node

Title source: llm
STIX 2.1

Description

WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet.

References (4)

Core 4
Core References
Third Party Advisory x_refsource_misc
https://github.com/wso2/product-apim/issues/7677
Third Party Advisory x_refsource_misc
https://github.com/wso2/docs-apim/issues/816

Scores

CVSS v3 9.8
EPSS 0.0209
EPSS Percentile 79.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-918
Status published
Products (2)
org.wso2.am/am-parent 0Maven
wso2/api_manager 3.0.0
Published May 20, 2020
Tracked Since Feb 18, 2026