Medium severity4.3NVD Advisory· Published Jun 23, 2025· Updated Jun 17, 2026
CVE-2024-3511
CVE-2024-3511
Description
An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, a malicious actor with access to the management console can exploit a specific bypass method to retrieve versioned files without proper authorization.
Successful exploitation of this vulnerability could lead to unauthorized disclosure of configuration or resource files that may be stored as registry versions, potentially aiding further attacks or system reconnaissance.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- WSO2/WSO2 API Managerv5Range: 3.1.0
- WSO2/WSO2 Carbon User Manager Kernelv5Range: 4.5.0
- WSO2/WSO2 Enterprise Integratorv5Range: 6.6.0
- WSO2/WSO2 Identity Serverv5Range: 5.10.0
- WSO2/WSO2 Identity Server as Key Managerv5Range: 5.10.0
- WSO2/WSO2 Open Banking AMv5Range: 2.0.0
- WSO2/WSO2 Open Banking IAMv5Range: 2.0.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.