CVE Database
/

CVE-2023-0456

Back to search

CVE-2023-0456

Published: Sep 27, 2023

Modified: Sep 24, 2024

PUBLISHED

CVSS v3.1

7.4

HIGH

Description

A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token from a separate realm. This could allow a separate realm to be accessible to an attacker, permitting access to unauthorized information.

VendorProductVersions

n/a

apicast

unaffected
2.13.2
unaffected
2.14.0
unaffected
2.12.2

Red Hat

Red Hat 3scale API Management Platform 2

All versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

None

References

RHBZ#2163586
issue-tracking
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now