cve/2019/CVE-2019-14836.md

19 lines
860 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2019-14836](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14836)
![](https://img.shields.io/static/v1?label=Product&message=Red%20Hat%203scale%20API%20Management&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20Red%20Hat%203scale%20API%20Management%202.10.0%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Cross-Site%20Request%20Forgery%20(CSRF)&color=brighgreen)
### Description
A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to access unauthorized information or conduct further attacks.
### POC
#### Reference
- https://bugzilla.redhat.com/show_bug.cgi?id=1847605
2024-06-09 00:33:16 +00:00
- https://bugzilla.redhat.com/show_bug.cgi?id=1847605
2024-05-26 14:27:05 +02:00
#### Github
No PoCs found on GitHub currently.