REDHAT-BUG-2238498: Medium severity red hat 3scale vulnerability
Published Sep 12, 2023
·Updated
Local machine/access vuln has been found in 3scale API Management where a users authentication tokens can be accessed after they have logged out, but only under very specific circumstances
https://issues.redhat.com/browse/THREESCALE-10076
Affected Software
1 affected component
Red Hat 3scale API Management
Event History
Sep 12, 2023
Data Sourced
via Red Hat·08:59 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2238498?
The severity of REDHAT-BUG-2238498 is classified as a local access vulnerability.
2
How do I fix REDHAT-BUG-2238498?
To fix REDHAT-BUG-2238498, ensure that users' authentication tokens are properly invalidated upon logout.
3
Who is affected by REDHAT-BUG-2238498?
REDHAT-BUG-2238498 affects users of Red Hat 3scale API Management.
4
What causes the vulnerability REDHAT-BUG-2238498?
The vulnerability REDHAT-BUG-2238498 is caused by authentication tokens not being properly cleared after user logout under specific conditions.
5
Can I exploit REDHAT-BUG-2238498 remotely?
No, REDHAT-BUG-2238498 is a local machine access vulnerability that requires physical or local access.