CVE-2024-6832: Account Lockout Failure via Secondary User Store Inaccessibility in Multiple WSO2 Products Allows Brute Force Attacks
The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attempt authentication with invalid credentials without triggering the lockout mechanism for users within active stores.
When the account locking mechanism is bypassed due to the inaccessibility of secondary user stores, users in accessible user stores are left vulnerable to brute force attacks. A malicious actor can exploit this by attempting numerous invalid password combinations against a user account without the expected account lockout consequence.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WSO2to a version that resolves this vulnerability.Patch WSO2-2024-3352
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6832?
CVE-2024-6832 has a medium severity rating of 5.9.
What are the potential risks associated with CVE-2024-6832?
CVE-2024-6832 allows attackers to perform brute force attacks due to an ineffective account lockout mechanism when secondary user stores are inaccessible.
How do I fix CVE-2024-6832?
To fix CVE-2024-6832, ensure all user stores are accessible and consider implementing additional security measures to mitigate brute force attacks.
What systems are affected by CVE-2024-6832?
CVE-2024-6832 affects multiple WSO2 products that utilize secondary user stores.
What is the impact of exploiting CVE-2024-6832?
Exploiting CVE-2024-6832 could allow an attacker to compromise accounts by repeatedly trying invalid credentials without triggering account lockout.