CVE-2020-14388: Medium severity red hat openshift api management vulnerability
A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were not properly enforced. This flaw allows an authenticated user to bypass normal account restrictions and access API services where they do not have permission.
Other sources
It was found that member permissions for an API's admin portal in 3scale were not properly enforced. An authenticated user could use this flaw to bypass normal account restrictions and access API services they do not have permissions for.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this flaw?
The vulnerability ID of this flaw is CVE-2020-14388.
What is the affected software?
The affected software is Red Hat 3scale API Management Platform version 2.0.
What is the severity of CVE-2020-14388?
The severity of CVE-2020-14388 is medium with a severity value of 6.3.
How does this flaw affect the Red Hat 3scale API Management Platform?
This flaw allows an authenticated user to bypass normal account restrictions and access API services where they do not have permission.
Is there a fix available for CVE-2020-14388?
Yes, a fix is available for CVE-2020-14388. Please refer to the reference link for more information.