Red Hat 3scale 2.10.0 ER1

CPE Details

Red Hat 3scale 2.10.0 ER1
2.10.0
2021-06-01
10h21 +00:00
2021-06-03
13h28 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:redhat:3scale:2.10.0:er1:*:*:*:*:*:*

Informations

Vendor

redhat

Product

3scale

Version

2.10.0

Update

er1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-3814 2022-03-25 17h02 +00:00 It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.
7.5
High
CVE-2021-3412 2021-06-01 11h47 +00:00 It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks.
7.3
High