CVE-2024-2321
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-2321 is an authorization vulnerability affecting multiple WSO2 products. It allows attackers to access protected APIs using a refresh token instead of the expected access token, bypassing authorization checks and token mapping. This means session cookies are not necessary for API access, increasing the risk of unauthorized operations. Exploitation necessitates obtaining a valid refresh token of an admin user, which, due to their longer expiration time, could result in prolonged unauthorized access to API resources, posing threats to data confidentiality and integrity.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.