The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWso2 Api Control Plane
APPWso24.5.0 – 4.5.0.58 (excl.)4.6.0 – 4.6.0.22 (excl.)Wso2 Api Manager
APPWso24.1.0 – 4.1.0.257 (excl.)4.2.0 – 4.2.0.197 (excl.)4.3.0 – 4.3.0.108 (excl.)4.4.0 – 4.4.0.72 (excl.)4.5.0 – 4.5.0.57 (excl.)4.6.0 – 4.6.0.21 (excl.)Wso2 Traffic Manager
APPWso24.5.0 – 4.5.0.56 (excl.)4.6.0 – 4.6.0.21 (excl.)Wso2 Universal Gateway
APPWso24.5.0 – 4.5.0.57 (excl.)4.6.0 – 4.6.0.21 (excl.)
Related vulnerabilities
WSO2 — nieograniczony upload plików i RCE przez path traversal
WSO2: niedostateczne ograniczenia tokenów użytkowników — dostęp do Admin REST API
Pominięcie uwierzytelniania wieloetapowego w WSO2 Conditional Authentication
WSO2 API Manager – RCE przez upload pliku z uprawnieniami administratora
Brak wymuszania uwierzytelniania mTLS w produktach WSO2 — nieautoryzowany dostęp administracyjny