Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5x39-cc3p-mj36

Опубликовано: 09 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invoice if the URL is known or guessed.

A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invoice if the URL is known or guessed.

EPSS

Процентиль: 49%
0.0026
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-538
CWE-862

Связанные уязвимости

CVSS3: 5.3
redhat
около 1 года назад

A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invoice if the URL is known or guessed.

CVSS3: 5.3
nvd
около 1 года назад

A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invoice if the URL is known or guessed.

EPSS

Процентиль: 49%
0.0026
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-538
CWE-862