Vulnerability Description
It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | 3Scale | All versions |
| Redhat | 3Scale Api Management | 2.0 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1928301Issue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1928301Issue TrackingVendor Advisory
FAQ
What is CVE-2021-3412?
CVE-2021-3412 is a vulnerability with a CVSS score of 7.3 (HIGH). It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduc...
How severe is CVE-2021-3412?
CVE-2021-3412 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3412?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat 3Scale, Redhat 3Scale Api Management.