First published: Thu Oct 10 2024(Updated: )
The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger. It could advise about the running version of a service to an attacker. The attacker could also check if a service is running.
Credit: zowe-security@lists.openmainframeproject.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linuxfoundation Zowe Api Mediation Layer | >=2.11.0<2.17.0 |
There is a fix since version 2.17.0, authentication is required for the endpoints.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.