Vulnerability Description
WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wso2 | Api Manager | 3.0.0 |
Related Weaknesses (CWE)
References
- https://docs.wso2.com/display/Security/Security+AdvisoriesVendor Advisory
- https://docs.wso2.com/display/Security/WSO2+Security+Vulnerability+Management+PrVendor Advisory
- https://github.com/wso2/docs-apim/issues/816Third Party Advisory
- https://github.com/wso2/product-apim/issues/7677Third Party Advisory
- https://docs.wso2.com/display/Security/Security+AdvisoriesVendor Advisory
- https://docs.wso2.com/display/Security/WSO2+Security+Vulnerability+Management+PrVendor Advisory
- https://github.com/wso2/docs-apim/issues/816Third Party Advisory
- https://github.com/wso2/product-apim/issues/7677Third Party Advisory
FAQ
What is CVE-2020-13226?
CVE-2020-13226 is a vulnerability with a CVSS score of 9.8 (CRITICAL). WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet.
How severe is CVE-2020-13226?
CVE-2020-13226 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-13226?
Check the references section above for vendor advisories and patch information. Affected products include: Wso2 Api Manager.