See how mulesoft compares to other vendors in security performance
MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership endpoint. An authenticated user can modify their group membership without proper authorization checks, allowing privilege escalation. An attacker can add themselves to arbitrary groups by supplying a valid group ID, which can be obtained via other application functionalities (e.g. /customer/servlet/mco/webapi/group/picker/groups), provided he has necessary permissions, or potentially inferred through brute-force techniques.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.
End of life: 2/28/2027, End of support: 11/30/2026, Latest version: 4.12.1
End of life: 10/31/2026, End of support: 7/31/2026, Latest version: 4.11.6
End of life: 6/30/2026, End of support: 3/31/2026, Latest version: 4.10.5
End of life: 2/28/2026, End of support: 11/30/2025, Latest version: 4.9.16
End of life: 2/29/2028, End of support: 8/31/2027, Latest version: 4.9.16
End of life: 6/30/2025, End of support: 3/31/2025, Latest version: 4.8.6
End of life: 2/28/2025, End of support: 10/31/2024, Latest version: 4.7.4
End of life: 10/31/2024, End of support: 6/30/2024, Latest version: 4.6.22
End of life: 10/31/2024, End of support: 6/30/2024, Latest version: 4.6.22
End of life: 2/28/2027, End of support: 8/31/2026, Latest version: 4.6.22
End of life: 6/30/2024, End of support: 2/29/2024, Latest version: 4.5.3
End of life: 6/30/2024, End of support: 2/29/2024, Latest version: 4.5.3
End of life: 10/8/2025, End of support: 10/8/2024, Latest version: 4.4.0-20250919
End of life: 10/8/2025, End of support: 10/8/2024, Latest version: 4.4.0-20250919
A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers to submit data which can lead to resource exhaustion.
End of life: 3/7/2025, End of support: 3/7/2023, Latest version: 4.3.0-20240424
End of life: 3/7/2025, End of support: 3/7/2023, Latest version: 4.3.0-20240424
Withdrawn Advisory This advisory has been withdrawn because it does not affected a package in a supported ecosystem. This link has been maintained to preserve external references.
Original Description
Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java
Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code.
The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections
Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released before August 1 2019, and all versions of MuleSoft API Gateway released before August 1 2019 allow remote attackers to read files accessible to the Mule process.
End of life: 5/2/2023, End of support: 5/2/2021, Latest version: 4.2.2-20221027
End of life: 5/2/2023, End of support: 5/2/2021, Latest version: 4.2.2-20221027
End of life: 11/2/2022, End of support: 11/2/2020, Latest version: 4.1.6-20240112
End of life: 11/2/2022, End of support: 11/2/2020, Latest version: 4.1.6-20240112
End of life: 3/20/2024, End of support: 3/20/2021, Latest version: 3.9.5-20240122
End of life: 3/20/2024, End of support: 3/20/2021, Latest version: 3.9.5-20240122
Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to gain administrator privileges and execute arbitrary code via a crafted request that adds a new user. NOTE: this issue was originally reported for ESB Runtime 3.5.1, but it originates in MMC.