First published: Tue Sep 12 2023(Updated: )
A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens page is rendered from the browser cache.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
=2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-4910.
The title of the vulnerability is '3scale-admin-portal: logged out users tokens can be accessed'.
A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens page is rendered from the browser cache.
The affected software is Redhat 3scale Api Management version 2.0.
The severity of the vulnerability is medium with a CVSS score of 5.5.