Lucene search

K
redhatRedHatRHSA-2017:1712
HistoryJul 06, 2017 - 5:04 p.m.

(RHSA-2017:1712) Important: Red Hat 3scale API Management Platform 2.0.0 security update

2017-07-0617:04:26
access.redhat.com
75

0.04 Low

EPSS

Percentile

92.1%

Red Hat 3scale API Management Platform 2.0 is a platform for the management of access and traffic for web-based APIs across a variety of deployment options.

Security Fix(es):

  • It was found that RH-3scale AMP would permit creation of an access token without a client secret. An attacker could use this flaw to circumvent authentication controls and gain access to restricted APIs. (CVE-2017-7512)

The underlying container image was also rebuilt to resolve other security issues. These were addressed via the following errata:

Red Hat would like to thank Ryan Nauman (TruCode) for reporting the CVE-2017-7512 issue.