CVE-2024-2374 Details
Description
The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entities. This omission allows malicious actors to craft XML payloads that exploit the parser's behavior, leading to the inclusion of external resources. By leveraging this vulnerability, an attacker can read confidential files from the file system and access limited HTTP resources reachable by the product. Additionally, the vulnerability can be exploited to perform denial of service attacks by exhausting server resources through recursive entity expansion or fetching large external resources.
A vulnerability exists in the XML parsers of multiple WSO2 products, including WSO2 API Manager, WSO2 Identity Server, and WSO2 Open Banking solutions. These parsers improperly handle user-supplied XML data, failing to prevent the resolution of external entities. This flaw enables attackers to craft XML payloads that exploit the parser's behavior, allowing access to external resources. Exploitation of this vulnerability could lead to unauthorized reading of confidential files from the file system, access to limited HTTP resources reachable by the product, or denial-of-service attacks by exhausting server resources through recursive entity expansion or by fetching large external resources.
Users of WSO2 products should update to the latest unaffected version. WSO2 Support Subscription Holders can use WSO2 Updates to apply the fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3255/ | WSO2 LLC | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | WSO2 LLC |
Affected Products
| Product | Versions |
|---|---|
| wso2 api manager | >= 3.1.0, < 3.1.0.278 >= 3.2.0, < 3.2.0.368 >= 4.0.0, < 4.0.0.280 >= 4.1.0, < 4.1.0.206 >= 4.2.0, < 4.2.0.144 >= 4.3.0, < 4.3.0.57 |
CPE
Remediation
| |
| wso2 identity server | >= 5.10.0, < 5.10.0.300 >= 5.11.0, < 5.11.0.329 >= 6.0.0, < 6.0.0.179 >= 6.1.0, < 6.1.0.136 |
CPE
Remediation
| |
| wso2 identity server as key manager | >= 5.10.0, < 5.10.0.296 |
CPE
Remediation
| |
| wso2 open banking am | >= 2.0.0, < 2.0.0.328 |
CPE
Remediation
| |
| wso2 open banking iam | >= 2.0.0, < 2.0.0.348 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | WSO2 LLC |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | Initial Analysis | [email protected] |
| Apr 16, 2026 | New CVE Received | WSO2 LLC |