Impact
A flaw in the Event Publisher output adapter causes configuration properties to be logged without proper validation or sanitization. This logging can capture sensitive data, such as user credentials, that should not appear in log files. The result is a leakage of confidential information, classified as a Sensitive Information Disclosure (CWE-532).
Affected Systems
The vulnerability affects several WSO2 products, including WSO2 API Control Plane, WSO2 API Manager, WSO2 Carbon Event Publisher Core, WSO2 Identity Server, WSO2 Identity Server as Key Manager, WSO2 Open Banking AM, WSO2 Open Banking IAM, WSO2 Traffic Manager, and WSO2 Universal Gateway. No specific software versions are listed, so all current releases are potentially impacted.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to gain access to the linked log files (wso2carbon), typically through privileged or local access. Once logged, the attacker can read the exposed credentials or other sensitive content. The attack vector is likely internal or acquired through compromise, rather than a remote exploitation path.
OpenCVE Enrichment