First published: Fri Aug 21 2020(Updated: )
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WSO2 API Manager | <=3.1.0 | |
WSO2 API Microgateway | =2.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-24589.
The severity of CVE-2020-24589 is critical.
CVE-2020-24589 affects WSO2 API Manager up to and including version 3.1.0 and WSO2 API Microgateway version 2.2.0.
CVE-2020-24589 allows XML External Entity (XXE) injection attacks.
To fix the vulnerability CVE-2020-24589, upgrade WSO2 API Manager to a version beyond 3.1.0 and upgrade WSO2 API Microgateway to a version beyond 2.2.0.