CVE-2024-1524Disclosure(wso2 / api_manager)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk that a local user store user's information may be replaced during the account provisioning process in cases where federated users share the same username as local users. There will be no impact on your deployment if any of the preconditions mentioned below are not met. Only when all the preconditions mentioned below are fulfilled could a malicious actor associate a targeted local user account with a federated IDP user account that they control. The Deployment should have: -An IDP configured for federated authentication with Silent JIT provisioning enabled. The malicious actor should have: -A fresh valid user account in the federated IDP that has not been used earlier. -Knowledge of the username of a valid user in the local IDP. -An account at the federated IDP matching the targeted local username.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • api_manager
  • identity_server

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-24); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
api_manageridentity_server

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-24: 1Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 102-2402-2803-01
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-241
General1
2026-02-281
Disclosure1
2026-03-011
Disclosure1
Full discourse3 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2024-1524 (CVSS:7.7, HIGH) is Undergoing Analysis. When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk ..https://nvd.nist.gov/vuln/detail/CVE-2024-1524 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2024-1524, noting its high CVSS score and risk associated with the Silent Just-In-Time Provisioning feature, but provides no PoC, exploit, or patch details.

    0000053
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2024-1524 (CVSS:7.7, HIGH) is Undergoing Analysis. When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk ..https://nvd.nist.gov/vuln/detail/CVE-2024-1524 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces that CVE‑2024‑1524, a high‑severity flaw related to Silent Just‑In‑Time Provisioning in federated IDPs, is under analysis, with no PoC, exploit, or patch details provided.

    0000041
    173 followersView on X
  • CVE@CVEnew
    General

    CVE-2024-1524 When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk that a local user store user's information may b… https://www.cve.org/CVERecord?id=CVE-2024-1524

    Post summary

    The text references CVE-2024-1524 but offers no substantive details, PoC, exploit, or mitigation information.

    00000138
    56.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appwso2api_manager---
Appwso2identity_server---

Explore more