The password update form on the developer portal doesn't require entering the previous password thus representing a vulnerability threat.
A pending session enable a malicious user to change the credentials of an account without any oblstacle.
- links to
-
RHEA-2023:117411 3scale-operator 0.11.7 for RHOAM
-
RHEA-2023:119803 Release of 3scale operator 0.11.8 for RHOAM - Containers
- mentioned on
(5 mentioned on)