CVE-2024-1524
7.7WSO2 · API Manager, Identity Server
A flaw in WSO2 products with Silent Just-In-Time Provisioning enabled allows federated users to potentially overwrite local user account information if usernames overlap.
Executive summary
A critical authentication bypass vulnerability in WSO2 API Manager and Identity Server allows attackers to hijack local user accounts through federated provisioning.
Vulnerability
This is an authentication bypass by spoofing (CWE-290) occurring when the Silent Just-In-Time provisioning feature is enabled, allowing an unauthenticated attacker to associate a local account with a federated identity they control.
Business impact
Successful exploitation permits an unauthorized party to gain control over existing local user accounts, potentially leading to unauthorized data access and privilege escalation. Given the CVSS score of 7.7, this vulnerability poses a significant risk to organizational identity management systems and the integrity of user authentication processes.
Remediation
Immediate Action: Upgrade to the patched versions provided in the WSO2 security advisory (WSO2-2024-3144) as soon as possible.
Proactive Monitoring: Monitor authentication logs for suspicious account linking activity or unexpected changes to local user profiles occurring during federated login events.
Compensating Controls: If immediate patching is not feasible, consider disabling the Silent Just-In-Time provisioning feature for federated identity providers until the software can be updated.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The risk associated with account hijacking in identity provider software is substantial, as it undermines the foundation of access control. Administrators are strongly advised to verify their current WSO2 deployments against the affected versions listed above and apply the vendor-supplied patches immediately to prevent potential account takeover attempts.