Beveiligingsadvies

CVE-2021-3814

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-03-25 18:02:50
Laatst bijgewerkt 2024-08-03 17:09:09
Toegewezen door redhat
CVSS-score geen score
Status PUBLISHED

Beschrijving

It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.