VYPR
Medium severity4.3NVD Advisory· Published Jun 23, 2025· Updated Jun 17, 2026

CVE-2024-3511

CVE-2024-3511

Description

An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, a malicious actor with access to the management console can exploit a specific bypass method to retrieve versioned files without proper authorization.

Successful exploitation of this vulnerability could lead to unauthorized disclosure of configuration or resource files that may be stored as registry versions, potentially aiding further attacks or system reconnaissance.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • WSO2/WSO2 API Managerv5
    Range: 3.1.0
  • WSO2/WSO2 Carbon User Manager Kernelv5
    Range: 4.5.0
  • WSO2/WSO2 Enterprise Integratorv5
    Range: 6.6.0
  • WSO2/WSO2 Identity Serverv5
    Range: 5.10.0
  • WSO2/WSO2 Identity Server as Key Managerv5
    Range: 5.10.0
  • WSO2/WSO2 Open Banking AMv5
    Range: 2.0.0
  • WSO2/WSO2 Open Banking IAMv5
    Range: 2.0.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.