Redhat 3Scale vulnerabilities

6 known vulnerabilities affecting redhat/3scale.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2021-3814HIGHCVSS 7.5fixed in 2.11.02022-03-25
CVE-2021-3814 [HIGH] CWE-862 CVE-2021-3814: It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.
nvd
CVE-2021-3752HIGHCVSS 7.1v2.02022-02-16
CVE-2021-3752 [HIGH] CWE-416 CVE-2021-3752: A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls conn A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
nvd
CVE-2019-14836HIGHCVSS 8.8v2.42021-05-26
CVE-2019-14836 [HIGH] CWE-352 CVE-2019-14836: A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection again A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to access unauthorized information or conduct further attacks.
nvd
CVE-2020-25634MEDIUMCVSS 5.4fixed in 2.10.0v2.10.02021-05-26
CVE-2020-25634 [MEDIUM] CWE-284 CVE-2020-25634: A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive information or modify service APIs. Versions before 3scale-2.10.0-ER1 are affected.
nvd
CVE-2020-10711MEDIUMCVSS 5.9v2.02020-05-22
CVE-2020-10711 [MEDIUM] CWE-476 CVE-2020-10711: A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the' ebitmap_netlbl_import' routine. While processing the CIPSO restricted bitmap tag in the 'cipso_v4_p
nvd
CVE-2019-14849MEDIUMCVSS 5.4fixed in 2.62019-12-12
CVE-2019-14849 [MEDIUM] CWE-201 CVE-2019-14849: A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the us A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain access to unauthorized information.
nvd