CVE-2019-14836: CSRF
Published May 26, 2021
·Updated
A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to access unauthorized information or conduct further attacks.
Affected Software
1 affected component
redhat 3scale=2.4
Event History
May 26, 2021
CVE Published
via MITRE·11:18 AM
Data Sourced
via MITRE·11:18 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-14836?
CVE-2019-14836 is a vulnerability found in the 3scale dev portal that allows unauthorized access and potential further attacks.
2
How severe is CVE-2019-14836?
CVE-2019-14836 has a severity rating of 8.8 (high) on the CVSS scale.
3
What software is affected by CVE-2019-14836?
Redhat 3scale version 2.4 is affected by CVE-2019-14836.
4
How can an attacker exploit CVE-2019-14836?
An attacker can exploit CVE-2019-14836 by using the lack of login CSRF protection in the 3scale dev portal to access unauthorized information or conduct further attacks.
5
Is there a fix available for CVE-2019-14836?
Yes, a fix for CVE-2019-14836 is available. Please refer to the provided reference for more information.