CVE-2024-9671 - CVE House
Back to Database
Status published Medium CVE-2024-9671

System: pdf invoices of the developer users can be seen if the url is known

Vulnerability Description

A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invoice if the URL is known or guessed.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-9671

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Red Hat 3scale API Management Platform 2
Vulnerable Versions:
2.13.0, 2.14.0

Timeline

Official Publish: October 9th, 2024
Last Modified: March 20th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)