important · RCE — WSO2
WSO2 confirms a JWT authentication bypass, while CISA describes the same CVE as an exploited upload-to-RCE flaw.
Affects
WSO2 API Manager, API Control Plane, Traffic Manager and Universal Gateway, Java-based API-management and gateway services.
WSO2’s account says an unsupported signing algorithm can yield administrative account takeover. CISA’s account instead names path traversal, unrestricted upload and remote code execution.
Detail and 2 sources
We do not know whether the CVE conflates two vulnerabilities or how the asserted upload path relates to the JWT flaw.