Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-3814

Опубликовано: 25 мар. 2022
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:3scale:*:*:*:*:*:*:*:*
Версия до 2.11.0 (исключая)

EPSS

Процентиль: 49%
0.00263
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-862
CWE-862

Связанные уязвимости

CVSS3: 6.3
redhat
больше 4 лет назад

It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.

CVSS3: 7.5
github
почти 4 года назад

It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.

EPSS

Процентиль: 49%
0.00263
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-862
CWE-862