CVE-2020-24590: Critical severity wso2 api manager vulnerability
Published Aug 21, 2020
·Updated
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.
Affected Software
2 affected components
WSO2 API Manager<=3.1.0
WSO2 API Microgateway=2.2.0
Event History
Aug 21, 2020
CVE Published
via MITRE·07:05 PM
Data Sourced
via MITRE·07:05 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2020-24590?
CVE-2020-24590 is a vulnerability in the Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 that allows XML Entity Expansion attacks.
2
What software is affected by CVE-2020-24590?
The affected software includes WSO2 API Manager versions up to and including 3.1.0 and WSO2 API Microgateway version 2.2.0.
3
What is the severity of CVE-2020-24590?
CVE-2020-24590 has a severity rating of 9.1 (critical).
4
How can XML Entity Expansion attacks be prevented in WSO2 API Manager and API Microgateway?
To prevent XML Entity Expansion attacks, it is recommended to apply the security patch provided by WSO2. Please refer to the WSO2 security advisory WSO2-2020-0742 for more information.
5
What is the CWE ID associated with CVE-2020-24590?
CVE-2020-24590 is associated with CWE ID 776.