Home

Description

The component accepts XML input through the publisher without disabling external entity resolution. This allows malicious actors to submit a crafted XML payload that exploits the unescaped external entity references. By leveraging this vulnerability, a malicious actor can read confidential files from the product's file system or access limited HTTP resources reachable via HTTP GET requests to the vulnerable product.

PUBLISHED Reserved 2024-08-20 | Published 2026-04-16 | Updated 2026-04-16 | Assigner WSO2




LOW: 3.5CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-611: Improper Restriction of XML External Entity Reference ('XXE')

Product status

Default status
unaffected

Any version before 3.2.0
unknown

3.2.0 (custom) before 3.2.0.397
affected

3.2.1 (custom) before 3.2.1.27
affected

4.0.0 (custom) before 4.0.0.310
affected

4.0.0 (custom) before 4.0.0.319
affected

4.1.0 (custom) before 4.1.0.171
affected

4.2.0 (custom) before 4.2.0.127
affected

4.3.0 (custom) before 4.3.0.39
affected

References

security.docs.wso2.com/...ty-advisories/2026/WSO2-2024-3581/ vendor-advisory

cve.org (CVE-2024-8010)

nvd.nist.gov (CVE-2024-8010)

Download JSON