Security features bypass in WSO2 Inc. products - #VU72505
Published: February 22, 2023
Vulnerability identifier: #VU72505
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass reCAPTCHA.
The vulnerability exists due to improper input validation of reCAPTCHA for Secondary Userstore Users. A remote attacker can bypass reCAPTCHA for the secondary user store users when SSO is enabled.
Affected software
WSO2 API Manager
WSO2 Identity Server
WSO2 Identity Server as Key Manager
WSO2 Identity Server
WSO2 Identity Server as Key Manager
Remediation
Install updates from vendor's website.