CVE-2024-8010 is an XML External Entity (XXE) vulnerability in a component that processes XML input from publishers without properly disabling external entity resolution. This flaw enables attackers to submit malicious XML payloads that exploit unescaped external entity references to read sensitive files from the affected product's file system or access HTTP resources available to the vulnerable server. The vulnerability carries a HIGH severity rating with a CVSS score of 7.5, reflecting a network-based attack vector requiring no authentication or user interaction, making it easily exploitable. The attack has high confidentiality impact as successful exploitation allows unauthorized access to sensitive files and resources, though integrity and availability are not affected. The vulnerability is currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and the Active Hot List, indicating active exploitation in the wild. However, the extremely low EPSS score of 0.000050000 suggests minimal community attention or publicly available exploit code at this time, despite the active exploitation status.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.2.0, < 3.2.0.397CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* | ||
>= 3.2.1, < 3.2.1.27CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* | ||
>= 4.0.0, <= 4.0.0.310CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* | ||
>= 4.1.0, < 4.1.0.171CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* | ||
>= 4.2.0, < 4.2.0.127CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.