PT-2020-13382 · Wso2 · Wso2 Api Manager

Published

2020-05-20

·

Updated

2022-05-24

·

CVE-2020-13226

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WSO2 API Manager version 3.0.0
Description The issue allows for improper restriction of outbound network access from a Publisher node, potentially leading to Server-Side Request Forgery (SSRF) attacks on the node's entire intranet.
Recommendations For WSO2 API Manager version 3.0.0, restrict outbound network access from the Publisher node to prevent SSRF attacks. As a temporary workaround, consider limiting access to the Publisher node to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13226
GHSA-JFGP-Q2HG-W285

Affected Products

Wso2 Api Manager