CVE-2023-6839: Medium severity wso2 api manager vulnerability
Published Dec 15, 2023
·Updated
Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in the HTTP response.
Affected Software
4 affected components
WSO2 API Manager=3.0.0
WSO2 API Manager=3.1.0
WSO2 API Manager=3.2.0
WSO2 API Manager=4.0.0
Remediation
Information
For WSO2 Subscription holders, the recommended solution is to apply the provided patch/update to the affected versions of the products. If there are any instructions given with the patch/update, please make sure those are followed properly.
Community users may apply the relevant fixes to the product based on the public fix(s) advertised in https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2022/WSO2-2021-1... https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2022/WSO2-2021-1334/
Event History
Dec 15, 2023
CVE Published
10:14 AM
Data Sourced
10:14 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-6839?
CVE-2023-6839 is categorized as a moderate severity vulnerability.
2
How do I fix CVE-2023-6839?
To resolve CVE-2023-6839, upgrade to a patched version of WSO2 API Manager that fixes the improper error handling issue.
3
Which versions of WSO2 API Manager are affected by CVE-2023-6839?
CVE-2023-6839 affects WSO2 API Manager versions 3.0.0, 3.1.0, 3.2.0, and 4.0.0.
4
What type of vulnerability is CVE-2023-6839?
CVE-2023-6839 is an improper error handling vulnerability that may expose sensitive internal information.
5
Is there a risk of information disclosure with CVE-2023-6839?
Yes, CVE-2023-6839 poses a risk of information disclosure by revealing internal package names in HTTP responses.