CVE-2021-3412
published 2021-06-01CVE-2021-3412: It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access…
PriorityP337high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.76%
51.1th percentile
It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | 3scale_api_management | — | — |
| redhat | 3scale_api_management | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jh24-r4rp-jw9m: It was found that all versions of 3Scale developer portal lacked brute force protections
ghsa_unreviewed·2022-05-24
CVE-2021-3412 [HIGH] CWE-307 GHSA-jh24-r4rp-jw9m: It was found that all versions of 3Scale developer portal lacked brute force protections
It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks.
Red Hat
3scale: lack of brute force protection on dev portal login
vendor_redhat·2021-02-12·CVSS 7.3
CVE-2021-3412 [HIGH] CWE-307 3scale: lack of brute force protection on dev portal login
3scale: lack of brute force protection on dev portal login
It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks.
A flaw was found in the 3scale developer portal, where it lacked brute force protections. This flaw allows an attacker to use this gap to bypass login controls and access privileged information, or possibly conduct further attacks. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Package: system (Red Hat 3scale API Management Platform 2) - Affected
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-06-01
Published