Red Hat Bugzilla – Bug 1457997
CVE-2017-7512 3scale AMP: validation bypass in oauth
Last modified: 2017-07-06 14:42:33 EDT
It was found that RH-3scale would permit creation of an access token without a client secret. An attacker could use this flaw to circumvent authentication controls and gain access to restricted APIs.
Acknowledgments: Name: Ryan Nauman (TruCode)
This issue has been addressed in the following products: 3scale AMP 2.0 Via RHSA-2017:1712 https://access.redhat.com/errata/RHSA-2017:1712