CVE-2023-4910: 3scale-admin-portal: logged out users tokens can be accessed
A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens page is rendered from the browser cache.
Other sources
Local machine/access vuln has been found in 3scale API Management where a users authentication tokens can be accessed after they have logged out, but only under very specific circumstances
https://issues.redhat.com/browse/THREESCALE-10076
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-4910.
What is the title of the vulnerability?
The title of the vulnerability is '3scale-admin-portal: logged out users tokens can be accessed'.
What is the description of the vulnerability?
A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens page is rendered from the browser cache.
What is the affected software?
The affected software is Redhat 3scale Api Management version 2.0.
What is the severity of the vulnerability?
The severity of the vulnerability is medium with a CVSS score of 5.5.