CVE-2024-9671

A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invoice if the URL is known or guessed.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:3scale_api_management_platform:2.0:*:*:*:*:*:*:*

History

04 Dec 2024, 08:15

Type Values Removed Values Added
CWE CWE-538

25 Nov 2024, 18:17

Type Values Removed Values Added
CPE cpe:2.3:a:redhat:3scale_api_management_platform:2.0:*:*:*:*:*:*:*
First Time Redhat 3scale Api Management Platform
Redhat
CWE CWE-862
References () https://access.redhat.com/security/cve/CVE-2024-9671 - () https://access.redhat.com/security/cve/CVE-2024-9671 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2317449 - () https://bugzilla.redhat.com/show_bug.cgi?id=2317449 - Issue Tracking, Vendor Advisory

10 Oct 2024, 12:51

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en 3Scale. No existe un mecanismo de autenticación para ver una factura en PDF de un usuario desarrollador si se conoce la URL. Cualquiera puede ver la factura si se conoce o se adivina la URL.

09 Oct 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-09 15:15

Updated : 2024-12-04 08:15


NVD link : CVE-2024-9671

Mitre link : CVE-2024-9671

CVE.ORG link : CVE-2024-9671


JSON object : View

Products Affected

redhat

  • 3scale_api_management_platform
CWE
CWE-862

Missing Authorization