Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NDefault status
affected
Description
A flaw was found in the 3scale Developer Portal. When creating or updating an account in the Developer Portal UI it is possible to modify fields explicitly configured as read-only or hidden, allowing an attacker to modify restricted information.
Problem types
Improper Preservation of Permissions
Product status
Timeline
| 2024-06-29: | Reported to Red Hat. |
| 2025-11-03: | Made public. |
References
access.redhat.com/security/cve/CVE-2024-12125
bugzilla.redhat.com/show_bug.cgi?id=2330214 (RHBZ#2330214)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.