5.3
CVE-2024-1248
- EPSS 0.18%
- Veröffentlicht 04.07.2026 20:38:49
- Zuletzt bearbeitet 09.07.2026 18:47:41
- CVE-Watchlists
- Unerledigt
Role Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enables Privilege Escalation
The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user. Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username. When these conditions are met, a malicious individual can leverage the JIT provisioning process to modify the roles of local users. The overwritten roles are limited to those defined within the federated IDP, typically granting minimal access rights unless explicitly configured otherwise by the federated IDP administrator.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wso2 ≫ Api Manager Version >= 3.0.0 < 3.0.0.153
Wso2 ≫ Api Manager Version >= 3.1.0 < 3.1.0.267
Wso2 ≫ Api Manager Version >= 3.2.0 < 3.2.0.351
Wso2 ≫ Api Manager Version >= 4.0.0 < 4.0.0.269
Wso2 ≫ Api Manager Version >= 4.1.0 < 4.1.0.169
Wso2 ≫ Identity Server Version >= 5.8.0 < 5.8.0.101
Wso2 ≫ Identity Server Version >= 5.9.0 < 5.9.0.138
Wso2 ≫ Identity Server Version >= 5.10.0 < 5.10.0.284
Wso2 ≫ Identity Server Version >= 5.11.0 < 5.11.0.321
Wso2 ≫ Identity Server As Key Manager Version >= 5.9.0 < 5.9.0.148
Wso2 ≫ Identity Server As Key Manager Version >= 5.10.0 < 5.10.0.280
Wso2 ≫ Open Banking Am Version >= 2.0.0 < 2.0.0.313
Wso2 ≫ Open Banking Iam Version >= 2.0.0 < 2.0.0.333
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.081 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
| ed10eef1-636d-4fbe-9993-6890dfa878f8 | 4.8 | 2.2 | 2.5 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
|
CWE-298 Improper Validation of Certificate Expiration
A certificate expiration is not validated or is incorrectly validated.
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3179/