3scale JWT vulnerability CWE-345 - Key confusion attack
Issue
Recent tests on 3scale have shown vulnerabilities related to CWE-345 that allow an attacker to perform key injection or key confusion attacks.
We would like to know if this issue has been resolved in later versions so that we can indicate it as the resolution for the identified vulnerability.
Environment
- Red Hat 3scale API Management
- 2.10 On-Premise or older
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.