System: pdf invoices of the developer users can be seen if the url is known
CVE-2024-9671
5.3MEDIUM
What is CVE-2024-9671?
A significant vulnerability exists in 3Scale that permits unauthorized access to PDF invoices of Developer users when the specific URL is known. This flaw arises from the absence of an authentication mechanism, allowing any person aware of or capable of guessing the invoice URL to gain access to sensitive billing information. Protecting this data is critical, as the exposure can lead to significant privacy concerns for affected users.