Vulnerability Details CVE-2021-3412
It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 50.5%
CVSS Severity
CVSS v3 Score 7.3
CVSS v2 Score 5.0
Products affected by CVE-2021-3412
-
cpe:2.3:a:redhat:3scale:-
-
cpe:2.3:a:redhat:3scale:2.0
-
cpe:2.3:a:redhat:3scale:2.10.0
-
cpe:2.3:a:redhat:3scale:2.11.0
-
cpe:2.3:a:redhat:3scale:2.4
-
cpe:2.3:a:redhat:3scale:2.6
-
cpe:2.3:a:redhat:3scale:2.7.0
-
cpe:2.3:a:redhat:3scale:2.8.0
-
cpe:2.3:a:redhat:3scale:2.8.1
-
cpe:2.3:a:redhat:3scale:2.9.0
-
cpe:2.3:a:redhat:3scale:2.9.1
-
cpe:2.3:a:redhat:3scale_api_management:2.0