important · WSO2 — privilege
Active exploitation turns an unsupported JWT algorithm into WSO2 administrative takeover.
Affects
WSO2 API Manager, API Control Plane, Traffic Manager and Universal Gateway, enterprise API-management and gateway services.
A network peer can present a forged token to an affected JWT-authenticated API. Once the verifier accepts it, the peer can invoke protected operations, obtain application credentials, and take management-plane control.
Detail and 2 sources
WSO2 has published fixed update levels for the affected products.