Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2024-1248

4.8 · MEDIUM
Published Jul 4, 2026 wso2 CWE-298 EPSS 0.30% (22th pctl)

Overview

CVE-2024-1248 is a medium-severity vulnerability affecting wso2 api_manager. It was published on July 4, 2026 and has a CVSS 3.1 base score of 4.8 (MEDIUM).

This vulnerability has a CVSS 3.1 base score of 4.8, rated MEDIUM. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user.

Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username. When these conditions are met, a malicious individual can leverage the JIT provisioning process to modify the roles of local users. The overwritten roles are limited to those defined within the federated IDP, typically granting minimal access rights unless explicitly configured otherwise by the federated IDP administrator.

Remediation

Check the references section for vendor advisories and patches from wso2. Update api_manager to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
wso2 api_manager >= 3.0.0, < 3.0.0.153 Affected
wso2 identity_server >= 5.8.0, < 5.8.0.101 Affected
wso2 identity_server_as_key_manager >= 5.9.0, < 5.9.0.148 Affected
wso2 open_banking_am >= 2.0.0, < 2.0.0.313 Affected
wso2 open_banking_iam >= 2.0.0, < 2.0.0.333 Affected

Frequently Asked Questions

What is CVE-2024-1248?

CVE-2024-1248 is a medium-severity vulnerability affecting wso2 api_manager. It was published on July 4, 2026 and has a CVSS 3.1 base score of 4.8 (MEDIUM).

How severe is CVE-2024-1248?

This vulnerability has a CVSS 3.1 base score of 4.8, rated MEDIUM. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2024-1248?

Check the references section for vendor advisories and patches from wso2. Update api_manager to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2024-1248?

CyberStrike's AI-powered security agents can automatically detect CVE-2024-1248 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.