MEDIUM
System: pdf invoices of the developer users can be seen if the url is known
Published Oct 9, 2024
5.3
MEDIUMCVSS 3.1
EPSS 0.28%
Description
A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invoice if the URL is known or guessed.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat 3scale API Management Platform 2 | affected |
|
- 2.0
No data.
Red Hat 3scale API Management Platform 2
3scale-amp-system-container
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat 3scale API Management Platform 2 | 3scale-amp-system-container | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://access.redhat.com/security/cve/CVE-2024-9671 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2317449 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-9671
- https://www.cve.org/CVERecord?id=CVE-2024-9671
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-9671 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2317449 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-9671 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-9671 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 9, 2024
Updated Mar 20, 2026
Reserved Oct 8, 2024
Link CVE-2024-9671
CISA Vulnrichment
Updated Oct 9, 2024