Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-10295

Опубликовано: 24 окт. 2024
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A malformed basic authentication header containing special characters bypasses authentication and allows unauthorized access to the backend. This issue can occur due to a failure in the base64 decoding process, which causes APICast to skip the rest of the authentication checks and proceed with routing the request upstream.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:3scale_api_management:2.0:*:*:*:*:*:*:*

EPSS

Процентиль: 19%
0.0006
Низкий

7.5 High

CVSS3

Дефекты

CWE-863
CWE-863

Связанные уязвимости

CVSS3: 7.5
redhat
больше 1 года назад

A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A malformed basic authentication header containing special characters bypasses authentication and allows unauthorized access to the backend. This issue can occur due to a failure in the base64 decoding process, which causes APICast to skip the rest of the authentication checks and proceed with routing the request upstream.

CVSS3: 5.9
github
больше 1 года назад

A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A malformed basic authentication header containing special characters bypasses authentication and allows unauthorized access to the backend. This issue can occur due to a failure in the base64 decoding process, which causes APICast to skip the rest of the authentication checks and proceed with routing the request upstream.

CVSS3: 5.9
fstec
больше 1 года назад

Уязвимость программного средства управления API-интерфейсами Red Hat 3scale API Management, связанная с недостатками механизма авторизации, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 19%
0.0006
Низкий

7.5 High

CVSS3

Дефекты

CWE-863
CWE-863