Описание
Capgo before 12.128.2 contains a weak parsing vulnerability in the x-limited-key-id header that allows attackers to bypass subkey enforcement by submitting malformed values, zero, or duplicate headers that result in NaN or falsy values. Remote attackers can manipulate the x-limited-key-id header to disable limited key scoping and execute requests using the main API key context instead of restricted subkey permissions.
EPSS
Процентиль: 27%
0.00345
Низкий
6.4 Medium
CVSS3
Дефекты
CWE-20
EPSS
Процентиль: 27%
0.00345
Низкий
6.4 Medium
CVSS3
Дефекты
CWE-20