Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-3814

It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 48.0%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2021-3814
  • Redhat » 3scale » Version: N/A
    cpe:2.3:a:redhat:3scale:-
  • Redhat » 3scale » Version: 2.0
    cpe:2.3:a:redhat:3scale:2.0
  • Redhat » 3scale » Version: 2.10.0
    cpe:2.3:a:redhat:3scale:2.10.0
  • Redhat » 3scale » Version: 2.4
    cpe:2.3:a:redhat:3scale:2.4
  • Redhat » 3scale » Version: 2.6
    cpe:2.3:a:redhat:3scale:2.6
  • Redhat » 3scale » Version: 2.7.0
    cpe:2.3:a:redhat:3scale:2.7.0
  • Redhat » 3scale » Version: 2.8.0
    cpe:2.3:a:redhat:3scale:2.8.0
  • Redhat » 3scale » Version: 2.8.1
    cpe:2.3:a:redhat:3scale:2.8.1
  • Redhat » 3scale » Version: 2.9.0
    cpe:2.3:a:redhat:3scale:2.9.0
  • Redhat » 3scale » Version: 2.9.1
    cpe:2.3:a:redhat:3scale:2.9.1


Contact Us

Shodan ® - All rights reserved