CVE-2024-10295 describes a critical authentication bypass vulnerability in Red Hat 3scale API Management's Gateway component. By sending a malformed, non-base64 "basic" authentication header containing special characters, an attacker can bypass authentication checks and gain unauthorized access to backend services. This flaw, rated 7.5 HIGH on the CVSS scale, requires no user interaction or prior privileges, and could lead to complete confidentiality compromise. While no public exploits or active exploitation have been observed, and community discussion is minimal, the potential for unauthorized access warrants immediate attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0CPE matchmatch criteria | cpe:2.3:a:redhat:3scale_api_management:2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.