CVE-2024-2321

MEDIUM

WSO2 API Manager and Identity Server - Incorrect Authorization via Refresh Token

Title source: llm
STIX 2.1

Description

An incorrect authorization vulnerability exists in multiple WSO2 products, allowing protected APIs to be accessed directly using a refresh token instead of the expected access token. Due to improper authorization checks and token mapping, session cookies are not required for API access, potentially enabling unauthorized operations. Exploitation requires an attacker to obtain a valid refresh token of an admin user. Since refresh tokens generally have a longer expiration time, this could lead to prolonged unauthorized access to API resources, impacting data confidentiality and integrity.

References (1)

Core 1

Scores

CVSS v3 5.6
EPSS 0.0022
EPSS Percentile 12.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (8)
org.wso2.am/am-parent 4.2.0-betaMaven
org.wso2.is/identity-server-parent 6.1.0-betaMaven
wso2/api_manager 4.0.0
wso2/api_manager 4.1.0
wso2/api_manager 4.2.0
wso2/identity_server 5.11.0
wso2/identity_server 6.0.0
wso2/identity_server 6.1.0
Published Feb 27, 2025
Tracked Since Feb 18, 2026