CVE-2024-52528

CRITICAL

Budget Control Gateway <1.5.2 - Auth Bypass

Title source: llm
STIX 2.1

Description

Budget Control Gateway acts as an entry point for incoming requests and routes them to the appropriate microservices for Budget Control. Budget Control Gateway does not properly validate auth tokens, which allows attackers to bypass intended restrictions. This vulnerability is fixed in 1.5.2.

References (1)

Core 1
Core References

Scores

CVSS v4 9.3
EPSS 0.0055
EPSS Percentile 41.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-285
Status published
Products (1)
BudgetControl/Gateway < 1.5.2
Published Nov 15, 2024
Tracked Since Feb 18, 2026