System: pdf invoices of the developer users can be seen if the url is known
CVE-2024-9671

5.3MEDIUM

Key Information:

Vendor
Red Hat
Vendor
CVE Published:
9 October 2024

Summary

A significant vulnerability exists in 3Scale that permits unauthorized access to PDF invoices of Developer users when the specific URL is known. This flaw arises from the absence of an authentication mechanism, allowing any person aware of or capable of guessing the invoice URL to gain access to sensitive billing information. Protecting this data is critical, as the exposure can lead to significant privacy concerns for affected users.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.