Host Header Injection Vulnerability in APIIDA API Gateway Manager by Broadcom
CVE-2023-50093

6.1MEDIUM

Key Information:

Vendor
Broadcom
Vendor
CVE Published:
3 January 2024

Summary

The APIIDA API Gateway Manager, a product offered by Broadcom, is exposed to a host header injection vulnerability in version 2023.2.2. This vulnerability allows an attacker to manipulate the host header in requests sent to the API Gateway, which may lead to unauthorized access or potentially redirecting traffic to malicious endpoints. Organizations utilizing this API Gateway should be aware of this security threat and implement necessary mitigations to safeguard their systems.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.