CVE-2017-7512

Impact:
Moderate
Public Date:
2017-07-06
CWE:
CWE-863
Bugzilla:
1457997: CVE-2017-7512 3scale AMP: validation bypass in oauth
It was found that RH-3scale AMP would permit creation of an access token without a client secret. An attacker could use this flaw to circumvent authentication controls and gain access to restricted APIs.

Find out more about CVE-2017-7512 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 6.5
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Impact Low
Availability Impact None

Red Hat Security Errata

Platform Errata Release Date
Red Hat 3scale API Management Platform 2.0 RHSA-2017:1712 2017-07-06

Acknowledgements

Red Hat would like to thank Ryan Nauman (TruCode) for reporting this issue.
Last Modified