Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-12125

Опубликовано: 03 нояб. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in the 3scale Developer Portal. When creating or updating an account in the Developer Portal UI it is possible to modify fields explicitly configured as read-only or hidden, allowing an attacker to modify restricted information.

Отчет

The impact of this issue depends on the use of the read-only or hidden fields by the provider, more specifically on the logic in the Developer Portal linked to these custom fields. Additionally, an attacker does not need to be authenticated to exploit this vulnerability. Due to these reasons, this flaw has been rated with an important severity.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-portaAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-281
https://bugzilla.redhat.com/show_bug.cgi?id=23302143scale-porta: Readonly fields not validated server-side

EPSS

Процентиль: 16%
0.00249
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
10 месяцев назад

A flaw was found in the 3scale Developer Portal. When creating or updating an account in the Developer Portal UI it is possible to modify fields explicitly configured as read-only or hidden, allowing an attacker to modify restricted information.

CVSS3: 5.4
github
10 месяцев назад

A flaw was found in the 3scale developer portal. This issue can allow account creation or updates passed through hidden or read-only fields, the contents of which may be altered. This flaw allows an attacker to access or modify restricted information.

EPSS

Процентиль: 16%
0.00249
Низкий

7.5 High

CVSS3