CVE-2020-13226: SSRF
Published May 20, 2020
·Updated
WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet.
Affected Software
2 affected components
maven/org.wso2.am:am-parent<=3.0.0
WSO2 API Manager=3.0.0
Event History
May 20, 2020
CVE Published
via MITRE·11:42 AM
Data Sourced
via MITRE·11:42 AM
Description
May 24, 2022
Advisory Published
05:18 PM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-13226.
2
What is the severity level of CVE-2020-13226?
The severity level of CVE-2020-13226 is critical (9.8).
3
How does WSO2 API Manager 3.0.0 restrict outbound network access?
WSO2 API Manager 3.0.0 does not properly restrict outbound network access.
4
What is the impact of CVE-2020-13226?
CVE-2020-13226 opens up the possibility of SSRF to the entire intranet of the Publisher node.
5
How can I fix this vulnerability?
To fix this vulnerability, you should update WSO2 API Manager to a version that properly restricts outbound network access.