A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were not properly enforced. This flaw allows an authenticated user to bypass normal account restrictions and access API services where they do not have permission.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1875553 | Issue Tracking Vendor Advisory |
Configurations
History
25 Jul 2022, 11:42
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-Other |
01 Jul 2021, 17:01
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 6.5
v3 : 6.3 |
10 Jun 2021, 18:29
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:redhat:3scale_api_management:2.0:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : 6.5
v3 : 8.8 |
References | (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1875553 - Issue Tracking, Vendor Advisory | |
CWE | CWE-284 |
02 Jun 2021, 13:36
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-06-02 13:15
Updated : 2024-02-04 21:47
NVD link : CVE-2020-14388
Mitre link : CVE-2020-14388
CVE.ORG link : CVE-2020-14388
JSON object : View
Products Affected
redhat
- 3scale_api_management
CWE