CVE-2024-2374

CRITICAL WAF: High
CVSS 9.1 Published: 2026-04-16
CWE-611

The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entities. This omission allows malicious actors to craft XML payloads that exploit the parser's behavior, leading to the inclusion of external resources. By leveraging this vulnerability, an attacker can read confidential files from the file system and access limited HTTP resources reachable by the product. Additionally, the vulnerability can be exploited to perform denial of service attacks by exhausting server resources through recursive entity expansion or fetching large external resources.

WAF Coverage Analysis

XML External Entity (XXE) High WAF Coverage

OWASP: A05:2021 Security Misconfiguration

941xxx - XSS / XXE

Affected Software

VendorProductVersion
wso2api_manager3.1.0 - 3.1.0.278
wso2api_manager3.2.0 - 3.2.0.368
wso2api_manager4.0.0 - 4.0.0.280
wso2api_manager4.1.0 - 4.1.0.206
wso2api_manager4.2.0 - 4.2.0.144
wso2api_manager4.3.0 - 4.3.0.57
wso2identity_server5.10.0 - 5.10.0.300
wso2identity_server5.11.0 - 5.11.0.329
wso2identity_server6.0.0 - 6.0.0.179
wso2identity_server6.1.0 - 6.1.0.136

References

Back to CVE Database