Sceawere

Vulnerability Detail

CVE-2024-6541UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WSO2 Class Mediator MessageContext Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
1d ago
Vendor
WSO2
Product
WSO2 Micro Integrator
Attack Type
CWE-20: Improper Input Validation
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated. This weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. The exact impact depends on how `messageContext` properties are utilized within the affected WSO2 products.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-08-06T22:16:40.557Z",
  "pubdate": "2026-08-06T22:16:40.557Z",
  "executiveSummary": "An improper input validation and sanitization vulnerability exists within the Class Mediator of affected WSO2 products. The flaw arises when messageContext properties are utilized to dynamically populate values without adequate validation or sanitization controls. This security deficiency allows authenticated users to potentially access, expose, or modify sensitive system data and information belonging to other users that should logically remain isolated between distinct system invocations. The overall impact of this vulnerability is directly dependent on the specific implementation and utilization of messageContext properties within the deployment context of the affected WSO2 products. Successful exploitation requires authentication, enabling an attacker with valid credentials to leverage the improper handling of dynamic values during runtime execution. This compromises data confidentiality and integrity boundaries across isolated sessions, potentially leading to unauthorized cross-invocation data disclosure and unintended modification of critical system state.",
  "technicalDetails": "The vulnerability stems from the Class Mediator's failure to properly validate or sanitize messageContext properties when they are referenced and processed to populate dynamic runtime values. The vulnerable component resides within the message processing pipeline, specifically inside the Class Mediator implementation handling internal message context properties in WSO2 products. The root cause is the lack of strict boundary checks and input sanitization mechanisms on properties stored and retrieved from the messageContext during mediation flows. When an authenticated user triggers a system invocation that interacts with the Class Mediator, maliciously crafted or improperly handled properties within the messageContext can persist or bleed across execution boundaries due to insufficient isolation. The attack flow begins with an authenticated user submitting a request designed to inject or manipulate specific properties within the messageContext. Because the Class Mediator fails to sanitize or restrict these dynamic values, subsequent or concurrent system invocations that share execution threads or context stores may process the tainted properties. This improper state handling allows the attacker to manipulate dynamic value resolution, leading to cross-invocation data leakage where sensitive information from one user's session is exposed to another, or system data is modified in an unintended manner. Exploitation requires the attacker to possess valid authentication credentials to interact with the mediation endpoints. Depending on the exact deployment configuration, the network exposure typically encompasses any interface capable of triggering mediation sequences handled by the Class Mediator. Post-exploitation impact includes the unauthorized disclosure of sensitive multi-tenant or multi-user data, unauthorized data tampering, and compromise of logical isolation guarantees between independent system invocations."
}
CVE-2024-6541: WSO2 Class Mediator MessageContext Vulnerability (MEDIUM Severity, CVSS: 6.8) - Sceawere