CVE-2020-24590: Improper Restriction of Recursive Entity References in DTDs (XML Entity Expansion)

Severity: Critical

CVSS Score: 9.1

The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.