GHSA-98jv-r7r8-3rqm · Severity: high — The XML parsers within multiple WSO2 products accept user-supplied XML data without properly...
The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entities. This omission allows malicious actors to craft XML payloads that exploit the parser's behavior, leading to the inclusion of external resources. By leveraging this vulnerability, an attacker can read confidential files from the file system and access limited HTTP resources reachable by the product. Additionally, the vulnerability can be exploited to perform denial of service attacks by exhausting server resources through recursive entity expansion or fetching large external resources.
Conclusion & alert: CVE-2024-2374 is rated Low Risk (30.4/100): CVSS High severity, with low exploitation likelihood (EPSS 0.01%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-16 | — | 0.01% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | ed10eef1-636d-4fbe-9993-6890dfa878f8 |
| 9.1 | 3.1 | CRITICAL |
|
3.9 | 5.2 | [email protected] |
GHSA-98jv-r7r8-3rqm · Severity: high — The XML parsers within multiple WSO2 products accept user-supplied XML data without properly...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| wso2 | api_manager | >= 3.1.0, < 3.1.0.278 | cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* |
| wso2 | api_manager | >= 3.2.0, < 3.2.0.368 | cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* |
| wso2 | api_manager | >= 4.0.0, < 4.0.0.280 | cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* |
| wso2 | api_manager | >= 4.1.0, < 4.1.0.206 | cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* |
| wso2 | api_manager | >= 4.2.0, < 4.2.0.144 | cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* |
| wso2 | api_manager | >= 4.3.0, < 4.3.0.57 | cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* |
| wso2 | identity_server | >= 5.10.0, < 5.10.0.300 | cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* |
| wso2 | identity_server | >= 5.11.0, < 5.11.0.329 | cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* |
| wso2 | identity_server | >= 6.0.0, < 6.0.0.179 | cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* |
| wso2 | identity_server | >= 6.1.0, < 6.1.0.136 | cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* |
| wso2 | identity_server_as_key_manager | >= 5.10.0, < 5.10.0.296 | cpe:2.3:a:wso2:identity_server_as_key_manager:*:*:*:*:*:*:*:* |
| wso2 | open_banking_am | >= 2.0.0, < 2.0.0.328 | cpe:2.3:a:wso2:open_banking_am:*:*:*:*:*:*:*:* |
| wso2 | open_banking_iam | >= 2.0.0, < 2.0.0.348 | cpe:2.3:a:wso2:open_banking_iam:*:*:*:*:*:*:*:* |