CVE Published: 09/10/2024 |
CVE Updated: 04/12/2024 |
CVE Year: 2024 Source: redhat |
Vendor: Red Hat |
Product: Red Hat 3scale API Management Platform 2 Status : PUBLISHED
CVE-2024-9671 Description
A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invoice if the URL is known or guessed.