The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger. It could advise about the running version of a service to an attacker. The attacker could also check if a service is running.
References
Link | Resource |
---|---|
https://github.com/zowe/api-layer |
Configurations
No configuration.
History
10 Oct 2024, 15:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-312 |
10 Oct 2024, 12:51
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
10 Oct 2024, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-10 08:15
Updated : 2024-10-10 15:35
NVD link : CVE-2024-9802
Mitre link : CVE-2024-9802
CVE.ORG link : CVE-2024-9802
JSON object : View
Products Affected
No product.
CWE
CWE-312
Cleartext Storage of Sensitive Information