Lucene search

K
cveRedhatCVE-2019-14836
HistoryMay 26, 2021 - 12:15 p.m.

CVE-2019-14836

2021-05-2612:15:10
CWE-352
redhat
web.nvd.nist.gov
38
2
3scale
dev portal
login
csrf
vulnerability
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.4

Confidence

High

EPSS

0.001

Percentile

31.5%

A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to access unauthorized information or conduct further attacks.

Affected configurations

Nvd
Vulners
Node
redhat3scaleMatch2.4
VendorProductVersionCPE
redhat3scale2.4cpe:2.3:a:redhat:3scale:2.4:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Red Hat 3scale API Management",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Red Hat 3scale API Management 2.10.0"
      }
    ]
  }
]

Social References

More

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.4

Confidence

High

EPSS

0.001

Percentile

31.5%

Related for CVE-2019-14836