CVE-2023-6839

Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in the HTTP response.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:wso2:api_manager:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.0.0:*:*:*:*:*:*:*

History

21 Dec 2023, 19:16

Type Values Removed Values Added
References () https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2022/WSO2-2021-1334/ - () https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2022/WSO2-2021-1334/ - Vendor Advisory
First Time Wso2
Wso2 api Manager
CPE cpe:2.3:a:wso2:api_manager:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:*
Summary
  • (es) Debido a un manejo inadecuado de errores, un recurso de API REST podría exponer un error del lado del servidor que contenga un nombre de paquete interno específico de WSO2 en la respuesta HTTP.

15 Dec 2023, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-15 11:15

Updated : 2023-12-21 19:16


NVD link : CVE-2023-6839

Mitre link : CVE-2023-6839

CVE.ORG link : CVE-2023-6839


JSON object : View

Products Affected

wso2

  • api_manager
CWE
CWE-209

Generation of Error Message Containing Sensitive Information