Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qh7g-57ww-6fq4

Опубликовано: 24 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A malformed basic authentication header containing special characters bypasses authentication and allows unauthorized access to the backend. This issue can occur due to a failure in the base64 decoding process, which causes APICast to skip the rest of the authentication checks and proceed with routing the request upstream.

A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A malformed basic authentication header containing special characters bypasses authentication and allows unauthorized access to the backend. This issue can occur due to a failure in the base64 decoding process, which causes APICast to skip the rest of the authentication checks and proceed with routing the request upstream.

EPSS

Процентиль: 19%
0.0006
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 7.5
redhat
больше 1 года назад

A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A malformed basic authentication header containing special characters bypasses authentication and allows unauthorized access to the backend. This issue can occur due to a failure in the base64 decoding process, which causes APICast to skip the rest of the authentication checks and proceed with routing the request upstream.

CVSS3: 7.5
nvd
больше 1 года назад

A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A malformed basic authentication header containing special characters bypasses authentication and allows unauthorized access to the backend. This issue can occur due to a failure in the base64 decoding process, which causes APICast to skip the rest of the authentication checks and proceed with routing the request upstream.

CVSS3: 5.9
fstec
больше 1 года назад

Уязвимость программного средства управления API-интерфейсами Red Hat 3scale API Management, связанная с недостатками механизма авторизации, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 19%
0.0006
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-863