CVE-2023-4910 describes a flaw in the Red Hat 3scale API Management Admin Portal where sensitive personal tokens can be exposed via browser cache after a user logs out and navigates back. This vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring user interaction, and potentially leading to high confidentiality impact. While the EPSS and FAUCET scores are low, suggesting limited immediate risk, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on the CISA KEV catalog. Community discussion and media coverage are minimal, indicating low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0CPE matchmatch criteria | cpe:2.3:a:redhat:3scale_api_management:2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.