CyberRota Analysis
AI-GeneratedWSO2 Identity Server is vulnerable due to improper management of refresh tokens in the user impersonation flow, allowing attackers with access tokens for impersonated users to obtain new access tokens. This weakness enables them to maintain unauthorized actions on behalf of legitimate users, undermining log integrity and traceability. Organizations using WSO2 Identity Server should prioritize addressing this vulnerability to mitigate risks associated with unauthorized access and user impersonation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained an access token for an impersonated user to leverage the refresh token grant to obtain new access tokens, extending their ability to act as the legitimate user. An attacker who gains access to an impersonated user's access token can exploit this weakness to renew their authorization. This results in the continued ability to perform actions on behalf of the actual user, compromising log integrity and traceability by masking the true actor.
Related CVEs
Other vulnerabilities affecting the same vendor(s)