Budget Control Gateway acts as an entry point for incoming requests and routes them to the appropriate microservices for Budget Control. Budget Control Gateway does not properly validate auth tokens, which allows attackers to bypass intended restrictions. This vulnerability is fixed in 1.5.2.
Metrics
Affected Vendors & Products
References
History
Fri, 15 Nov 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Budgetcontrol
Budgetcontrol gateway |
|
CPEs | cpe:2.3:a:budgetcontrol:gateway:*:*:*:*:*:*:*:* | |
Vendors & Products |
Budgetcontrol
Budgetcontrol gateway |
|
Metrics |
ssvc
|
Fri, 15 Nov 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Budget Control Gateway acts as an entry point for incoming requests and routes them to the appropriate microservices for Budget Control. Budget Control Gateway does not properly validate auth tokens, which allows attackers to bypass intended restrictions. This vulnerability is fixed in 1.5.2. | |
Title | Auth Token can be passed dummy or wrong the middleware response is 200 OK | |
Weaknesses | CWE-285 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-11-15T16:21:56.073Z
Updated: 2024-11-15T17:14:10.451Z
Reserved: 2024-11-11T18:49:23.561Z
Link: CVE-2024-52528
Vulnrichment
Updated: 2024-11-15T17:14:05.441Z
NVD
Status : Received
Published: 2024-11-15T17:15:23.400
Modified: 2024-11-15T17:15:23.400
Link: CVE-2024-52528
Redhat
No data.