MEDIUM
3scale-system: API docs accessible without permissions
Published May 26, 2021
6.3
MEDIUMCVSS 3.1
EPSS 0.52%
Description
A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive information or modify service APIs. Versions before 3scale-2.10.0-ER1 are affected.
Affected products
- Vendor n/a Product 3scale-System Defaultunknown
Affected
- before 3scale-2.10.0-ER1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | 3scale-System | unknown | Affected
|
No data.
Red Hat 3scale API Management Platform 2
system
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat 3scale API Management Platform 2 | system | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://access.redhat.com/security/cve/CVE-2020-25634 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1880201 x_refsource_MISCIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-18304 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-25634
- https://www.cve.org/CVERecord?id=CVE-2020-25634
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-25634 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1880201 | x_refsource_MISCIssue TrackingVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-18304 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-25634 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-25634 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 26, 2021
Updated Aug 4, 2024
Reserved Sep 16, 2020
Link CVE-2020-25634
CISA Vulnrichment
No data
GitHub
No data