CVE-2023-0456
27.09.2023, 15:16
A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token from a separate realm. This could allow a separate realm to be accessible to an attacker, permitting access to unauthorized information.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | apicast | 𝑥 < 2.12.2 |
redhat | apicast | 2.13.0 ≤ 𝑥 < 2.13.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-285 - Improper AuthorizationThe software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
- CWE-862 - Missing AuthorizationThe software does not perform an authorization check when an actor attempts to access a resource or perform an action.