It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2004322 | Issue Tracking Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2004322 | Issue Tracking Vendor Advisory |
Configurations
History
21 Nov 2024, 06:22
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugzilla.redhat.com/show_bug.cgi?id=2004322 - Issue Tracking, Vendor Advisory |
Information
Published : 2022-03-25 19:15
Updated : 2024-11-21 06:22
NVD link : CVE-2021-3814
Mitre link : CVE-2021-3814
CVE.ORG link : CVE-2021-3814
JSON object : View
Products Affected
redhat
- 3scale
CWE
CWE-862
Missing Authorization