CVE-2020-25634: Medium severity red hat 3scale vulnerability
3scale's API docs URL is accessible without credentials. An attacker could use this flaw to view sensitive information or modify service APIs.
Other sources
A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive information or modify service APIs. Versions before 3scale-2.10.0-ER1 are affected.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-25634?
CVE-2020-25634 is a vulnerability found in Red Hat 3scale’s API docs URL, allowing unauthorized access and potential information disclosure or API modification.
How does CVE-2020-25634 affect Red Hat 3scale?
CVE-2020-25634 affects Red Hat 3scale by allowing unauthorized access to the API docs URL without the need for credentials.
What is the severity of CVE-2020-25634?
CVE-2020-25634 has a severity rating of medium, with a CVSS score of 5.4.
Which versions of Red Hat 3scale are affected by CVE-2020-25634?
Versions before 3scale-2.10.0-ER1 are affected by CVE-2020-25634.
How can I fix CVE-2020-25634?
To fix CVE-2020-25634, upgrade to version 3scale-2.10.0-ER1 or later.