REDHAT-BUG-2258456: Medium severity red hat 3scale api management vulnerability

Published Jan 15, 2024
·
Updated

A vulnerability was found in 3Scale when using with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the authtype is use3scaleoidcissuerendpoint, Token Introspection policy discovers the Token Introspection endpoint from the tokenintrospectionendpoint field, but the field was removed on RH-SSO 7.5. As the result, the policy doesn't inspect tokens; it determines that all tokens are valid.

Using an alternate authtype: authtype: clientid+clientsecret. Disabling the policy entirely might be a temporary solution if the alternate {{authtype is not feasible for some reason. The only purpose the token introspection endpoint serves is for sessions which are revoked in RH SSO before the standard TTL expires via the exp claim.

Affected Software

2 affected components
Red Hat 3scale>=15
Red Hat RH-SSO>=7.5.0

Event History

Jan 15, 2024
Data Sourced
via Red Hat·01:16 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2258456?

The vulnerability REDHAT-BUG-2258456 is categorized as a moderate severity issue.

2

How do I fix REDHAT-BUG-2258456?

To fix REDHAT-BUG-2258456, users should update to the latest version of Red Hat 3Scale or Red Hat RH-SSO that addresses the identified vulnerability.

3

What versions are affected by REDHAT-BUG-2258456?

REDHAT-BUG-2258456 affects Red Hat 3Scale starting from version 15 and Red Hat RH-SSO from version 7.5.0.

4

What types of software does REDHAT-BUG-2258456 impact?

REDHAT-BUG-2258456 impacts both Red Hat 3Scale and Red Hat Single Sign-On (RH-SSO) software.

5

What is the cause of REDHAT-BUG-2258456?

The cause of REDHAT-BUG-2258456 is the use of the removed token_introspection_endpoint field when auth_type is set to use_3scale_oidc_issuer_endpoint.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203