CVE-2022-1414
published 2022-10-19CVE-2022-1414: 3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user could use this flaw to inject scripts and…
PriorityP347high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.76%
51.2th percentile
3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user could use this flaw to inject scripts and possibly gain access to sensitive information or conduct further attacks.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | 3scale_api_management | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c7ff-fqm5-qq8j: 3scale API Management 2 does not perform adequate sanitation for user input in multiple fields
ghsa_unreviewed·2022-10-19
CVE-2022-1414 [HIGH] CWE-1173 GHSA-c7ff-fqm5-qq8j: 3scale API Management 2 does not perform adequate sanitation for user input in multiple fields
3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user could use this flaw to inject scripts and possibly gain access to sensitive information or conduct further attacks.
Red Hat
3scale-system: script injection in multiple endpoints
vendor_redhat·2022-04-19·CVSS 8.8
CVE-2022-1414 [HIGH] CWE-1173 3scale-system: script injection in multiple endpoints
3scale-system: script injection in multiple endpoints
3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user could use this flaw to inject scripts and possibly gain access to sensitive information or conduct further attacks.
Package: 3scale-amp-system (Red Hat 3scale API Management Platform 2) - Will not fix
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-19
Published