wso2/carbon-identity-framework

wso2/carbon-identity-framework

Releases5.21K
Frequency17 hours
Last Release
Stars135

CVE History

CVEPublishedCVSS v3CVSS v2
9.1 CRITICAL6.4 MEDIUM

XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0, 5.10.0, and 5.11.0. Allows attackers to gain read access to sensitive information or cause a denial of service via crafted GET requests.