Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3814

Опубликовано: 22 сент. 2021
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.

A flaw was found in 3scale's API docs, where it does not validate the access token. In the case of an invalid token, it uses session auth instead. This issue possibly bypasses access controls and permits unauthorized information disclosure.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=20043223scale: missing validation of access token

EPSS

Процентиль: 65%
0.01158
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.

CVSS3: 7.5
github
больше 4 лет назад

It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.

EPSS

Процентиль: 65%
0.01158
Низкий

6.3 Medium

CVSS3