5.3

CVE-2024-1248

Role Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enables Privilege Escalation

The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user.

Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username. When these conditions are met, a malicious individual can leverage the JIT provisioning process to modify the roles of local users. The overwritten roles are limited to those defined within the federated IDP, typically granting minimal access rights unless explicitly configured otherwise by the federated IDP administrator.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wso2Api Manager Version >= 3.0.0 < 3.0.0.153
Wso2Api Manager Version >= 3.1.0 < 3.1.0.267
Wso2Api Manager Version >= 3.2.0 < 3.2.0.351
Wso2Api Manager Version >= 4.0.0 < 4.0.0.269
Wso2Api Manager Version >= 4.1.0 < 4.1.0.169
Wso2Identity Server Version >= 5.8.0 < 5.8.0.101
Wso2Identity Server Version >= 5.9.0 < 5.9.0.138
Wso2Identity Server Version >= 5.10.0 < 5.10.0.284
Wso2Identity Server Version >= 5.11.0 < 5.11.0.321
Wso2Identity Server As Key Manager Version >= 5.9.0 < 5.9.0.148
Wso2Identity Server As Key Manager Version >= 5.10.0 < 5.10.0.280
Wso2Open Banking Am Version >= 2.0.0 < 2.0.0.313
Wso2Open Banking Iam Version >= 2.0.0 < 2.0.0.333
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.081
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
ed10eef1-636d-4fbe-9993-6890dfa878f8 4.8 2.2 2.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
CWE-298 Improper Validation of Certificate Expiration

A certificate expiration is not validated or is incorrectly validated.

https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3179/
Vendor Advisory