VulnerabilityModified
CVE-2020-14446
An issue was discovered in WSO2 Identity Server through 5.10.0 and WSO2 IS as Key Manager through 5.10.0.
MEDIUM 6.1EPSS 0.81%
Does this matter?
Lower severity and a low EPSS score (0.81%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in WSO2 Identity Server through 5.10.0 and WSO2 IS as Key Manager through 5.10.0. An open redirect exists.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.81% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- wso2/identity server · wso2/identity server as key manager
- Source
- cve@mitre.org
References
- https://cybersecurityworks.com/zerodays/cve-2020-14446-wso2.htmlExploit, Third Party Advisory
- https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2020-0713Vendor Advisory
- https://cybersecurityworks.com/zerodays/cve-2020-14446-wso2.htmlExploit, Third Party Advisory
- https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2020-0713Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.