CVE-2020-24589: XEE
Published Aug 21, 2020
·Updated
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.
Affected Software
2 affected components
WSO2 API Manager<=3.1.0
WSO2 API Microgateway=2.2.0
Remediation
Event History
Aug 21, 2020
CVE Published
via MITRE·07:06 PM
Data Sourced
via MITRE·07:06 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-24589.
2
What is the severity of CVE-2020-24589?
The severity of CVE-2020-24589 is critical.
3
Which software versions are affected by CVE-2020-24589?
CVE-2020-24589 affects WSO2 API Manager up to and including version 3.1.0 and WSO2 API Microgateway version 2.2.0.
4
What type of attack does CVE-2020-24589 allow?
CVE-2020-24589 allows XML External Entity (XXE) injection attacks.
5
How can I fix the vulnerability CVE-2020-24589?
To fix the vulnerability CVE-2020-24589, upgrade WSO2 API Manager to a version beyond 3.1.0 and upgrade WSO2 API Microgateway to a version beyond 2.2.0.