Budget Control Gateway acts as an entry point for incoming requests and routes them to the appropriate microservices for Budget Control. Budget Control Gateway does not properly validate auth tokens, which allows attackers to bypass intended restrictions. This vulnerability is fixed in 1.5.2.
Metrics
Affected Vendors & Products
References
History
Fri, 15 Nov 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Budgetcontrol
Budgetcontrol gateway |
|
CPEs | cpe:2.3:a:budgetcontrol:gateway:*:*:*:*:*:*:*:* | |
Vendors & Products |
Budgetcontrol
Budgetcontrol gateway |
|
Metrics |
ssvc
|
Fri, 15 Nov 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Budget Control Gateway acts as an entry point for incoming requests and routes them to the appropriate microservices for Budget Control. Budget Control Gateway does not properly validate auth tokens, which allows attackers to bypass intended restrictions. This vulnerability is fixed in 1.5.2. | |
Title | Auth Token can be passed dummy or wrong the middleware response is 200 OK | |
Weaknesses | CWE-285 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-11-15T17:14:10.451Z
Reserved: 2024-11-11T18:49:23.561Z
Link: CVE-2024-52528

Updated: 2024-11-15T17:14:05.441Z

Status : Awaiting Analysis
Published: 2024-11-15T17:15:23.400
Modified: 2024-11-18T17:11:56.587
Link: CVE-2024-52528

No data.