Lucene search

K
cvelistRedhatCVELIST:CVE-2019-14836
HistoryMay 26, 2021 - 11:18 a.m.

CVE-2019-14836

2021-05-2611:18:13
redhat
www.cve.org
4
3scale
portal
csrf
vulnerability
unauthorized information
attacks

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

31.5%

A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to access unauthorized information or conduct further attacks.

CNA Affected

[
  {
    "product": "Red Hat 3scale API Management",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Red Hat 3scale API Management 2.10.0"
      }
    ]
  }
]

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

31.5%

Related for CVELIST:CVE-2019-14836