Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(no matching packages found)
Permalink CVE-2025-14561
9.0 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations

In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.

Affected products

WSO2 API Manager
  • <4.3.0.93
  • <4.5.0.41
  • <4.2.0.182
  • <4.6.0.6
  • <4.1.0.242
  • <4.4.0.57
WSO2 Traffic Manager
  • <4.5.0.40
  • <4.6.0.6
WSO2 API Control Plane
  • <4.5.0.42
  • <4.6.0.7
WSO2 Universal Gateway
  • <4.5.0.40
  • <4.6.0.6
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl
  • <9.20.74.388
  • =<*
  • <9.29.120.213
  • <9.30.67.135
  • <9.32.147.5
  • <9.28.116.395
  • <9.31.86.108
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.util
  • <9.20.74.388
  • =<*
  • <9.29.120.213
  • <9.30.67.135
  • <9.32.147.5
  • <9.28.116.395
  • <9.31.86.108