AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-10295

HIGH · CVSS 7.5 EPSS 0.39%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-10-24 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. See the original NVD description below for full technical details.

CVE
CVE-2024-10295
Severity
HIGH
CVSS
7.5
EPSS
0.39%

Original NVD Description

A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A malformed basic authentication header containing special characters bypasses authentication and allows unauthorized access to the backend. This issue can occur due to a failure in the base64 decoding process, which causes APICast to skip the rest of the authentication checks and proceed with routing the request upstream.

Related CVEs

Other vulnerabilities affecting the same vendor(s)