CVE-2024-2374 is an XML External Entity (XXE) injection vulnerability affecting multiple WSO2 products. The flaw stems from improper XML parser configuration that fails to disable external entity resolution, enabling attackers to supply malicious XML payloads that reference external resources. This misconfiguration creates a critical security gap in how these products process user-supplied XML data. The vulnerability carries a CVSS score of 9.1 (CRITICAL) with a network-based attack vector requiring no authentication or user interaction. The attack complexity is low, meaning exploitation can be executed reliably by threat actors. An attacker can leverage this vulnerability to conduct information disclosure attacks by reading sensitive files from the file system, access HTTP resources available to the affected product, and execute denial of service attacks through resource exhaustion via recursive entity expansion or fetching large external resources. Currently, this vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and shows no signs of active exploitation in the wild. The EPSS score of 0.00014 indicates minimal current exploitation probability. However, the moderate FAUCET Risk Score of 43.0/100 suggests organizations should prioritize patching, particularly those operating internet-facing WSO2 deployments, as the straightforward nature of XXE exploitation combined with critical impact warrants prompt remediation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.1.0, < 3.1.0.278CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* | ||
>= 3.2.0, < 3.2.0.368CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.0.0.280CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* | ||
>= 4.1.0, < 4.1.0.206CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* | ||
>= 4.2.0, < 4.2.0.144CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.