GHSA-wg82-w434-qwgqMediumCVSS 5.3

A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes...

Published
August 11, 2026
Last Modified
August 11, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in acm-search-v2-api-rhel9. When the getFederationConfig function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results, leading to information disclosure.

🔗 References (4)