CVE-2024-9671
EUVD-2024-5045109.10.2024, 15:15
A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invoice if the URL is known or guessed.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | 3scale_api_management_platform | 2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration