CVE-2023-28640 is a low-severity vulnerability in Apiman, an open-source API Management platform. An authenticated Apiman Manager account can potentially access API keys they lack permission for by guessing specific resource URLs, which include Organization ID, Client ID, and Client Version. This could lead to unauthorized use of other users' resources, depending on system configuration. The attack requires high attack complexity due to the need for guessing or brute-forcing specific identifiers, and its impact is limited to confidentiality. The CVSS score is 3.1 (LOW), indicating a low risk. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage. Users are advised to upgrade to Apiman 3.1.0.Final or restrict account access as a workaround.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.0CPE matchmatch criteria | cpe:2.3:a:apiman:apiman:3.0.0:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.