It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2004322 | Issue Tracking Vendor Advisory |
Configurations
Information
Published : 2022-03-25 12:15
Updated : 2022-04-07 05:22
NVD link : CVE-2021-3814
Mitre link : CVE-2021-3814
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
redhat
- 3scale