First published: Thu Oct 10 2024(Updated: )
The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers.
Credit: zowe-security@lists.openmainframeproject.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linuxfoundation Zowe Api Mediation Layer | >=1.0.0<1.28.8 | |
Linuxfoundation Zowe Api Mediation Layer | >=2.0.0<2.18.0 |
In version 2.18.0 set configuration property `apiml.health.protected` to `true` to require authentication or upgrade to version 3.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.