Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-46fh-44xx-6xgh

Опубликовано: 26 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.

It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.

EPSS

Процентиль: 49%
0.00263
Низкий

7.5 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.3
redhat
больше 4 лет назад

It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.

CVSS3: 7.5
nvd
почти 4 года назад

It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.

EPSS

Процентиль: 49%
0.00263
Низкий

7.5 High

CVSS3

Дефекты

CWE-862