Bug 1880201 (CVE-2020-25634)

Summary: CVE-2020-25634 3scale-system: API docs accessible without permissions
Product: [Other] Security Response Reporter: Chess Hazlett <chazlett>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: amasferr, chazlett
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: 3scale-2.10.0-ER1 Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive information or modify service APIs.
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-05-24 18:08:36 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1875533    

Description Chess Hazlett 2020-09-17 22:49:55 UTC
3scale's API docs URL is accessible without credentials. An attacker could use this flaw to view sensitive information or modify service APIs.