Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.4epss 0.1%
exploitation probability
0.1%top 99% of all CVEs
observed exploitation
nono source reports it
The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET method for these operations, and while the SameSite=Lax cookie attribute is employed for mitigation, this mechanism is bypassed as it permits cookies to be sent with cross-origin top-level navigation requests, including GET requests. This allows an attacker to trick an authenticated user's browser into unknowingly executing unintended actions.
An attacker can exploit this vulnerability to perform unauthorized state-altering requests on behalf of authenticated users. This could lead to consequences such as data modification, account changes, or other actions that could result in data compromise or loss of user control over their account. However, this attack is only feasible if the Carbon console and related services are exposed to the public internet, which is not recommended according to WSO2's security guidelines.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Affected products
WSO2 · WSO2 API Control PlaneWSO2 · WSO2 API ManagerWSO2 · WSO2 Carbon Command Mediator UIWSO2 · WSO2 Carbon Component Andes Event UIWSO2 · WSO2 Carbon Component Andes UI1WSO2 · WSO2 Carbon Email Verification UIWSO2 · WSO2 Carbon Endpoint Editor UIWSO2 · WSO2 Carbon Eventing UIWSO2 · WSO2 Carbon Event Simulator UIWSO2 · WSO2 Carbon Execution Manager UIWSO2 · WSO2 Carbon GovernanceWSO2 · WSO2 Carbon Governance Custom Lifecycle Checklist UIWSO2 · WSO2 Carbon Governance Generic Artifact User InterfaceWSO2 · WSO2 Carbon Governance Life Cycles User InterfaceWSO2 · WSO2 Carbon Governance WSDL Tool UIWSO2 · WSO2 Carbon HL7 Business Messaging Store UIWSO2 · WSO2 Carbon HumanTask UIWSO2 · WSO2 Carbon Identity Entitlement UIWSO2 · WSO2 Carbon Identity Management UI1WSO2 · WSO2 Carbon Identity User Store Configuration UIWSO2 · WSO2 Carbon Logging UIWSO2 · WSO2 Carbon New Data Sources UIWSO2 · WSO2 Carbon Publish Event Mediator Configuration UIWSO2 · WSO2 Carbon Registry IndexingWSO2 · WSO2 Carbon Registry Info UI2WSO2 · WSO2 Carbon Registry Profiles UIWSO2 · WSO2 Carbon Registry Properties UIWSO2 · WSO2 Carbon Registry Relations UIWSO2 · WSO2 Carbon Registry Resources UIWSO2 · WSO2 Carbon Registry Search UIWSO2 · WSO2 Carbon Rest API Admin UIWSO2 · WSO2 Carbon Rule Mediator UIWSO2 · WSO2 Carbon Security UIWSO2 · WSO2 Carbon Sequence Editor UIWSO2 · WSO2 Carbon Tasks CoreWSO2 · WSO2 Carbon Task UIWSO2 · WSO2 Carbon Template Editor UIWSO2 · WSO2 Carbon Throttle Mediator UIWSO2 · WSO2 Enterprise IntegratorWSO2 · WSO2 Identity ServerWSO2 · WSO2 Identity Server as Key ManagerWSO2 · WSO2 Open Banking AMWSO2 · WSO2 Open Banking IAMWSO2 · WSO2 Stratos SSO Redirector UI ComponentWSO2 · WSO2 Stratos User Interface For Tenant CRUD OperationsWSO2 · WSO2 Traffic ManagerWSO2 · WSO2 Universal Gateway