WSO2 developers have released security advisory
WSO2 developers have released security advisory to address critical vulnerability (CVE-2022-29464) that impacts WSO2 API Manager, WSO2 Identity Server, WSO2 Enterprise Integrator, and WSO2 Open Banking products. A malicious actor could exploit this vulnerability to trigger arbitrary file upload and remote code execution.
More information on vulnerability and updates is available in WSO2 security advisory – wso2.com.
28 April 2022