CVE-2019-14836

HIGH

3scale - Cross-Site Request Forgery in Dev Portal Login

Title source: llm
STIX 2.1

Description

A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to access unauthorized information or conduct further attacks.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1847605

Scores

CVSS v3 8.8
EPSS 0.0013
EPSS Percentile 32.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
redhat/3scale 2.4
Published May 26, 2021
Tracked Since Feb 18, 2026