Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3412

Опубликовано: 12 фев. 2021
Источник: redhat
CVSS3: 5.6
EPSS Низкий

Описание

It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks.

A flaw was found in the 3scale developer portal, where it lacked brute force protections. This flaw allows an attacker to use this gap to bypass login controls and access privileged information, or possibly conduct further attacks. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 2systemAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-307
https://bugzilla.redhat.com/show_bug.cgi?id=19283013scale: lack of brute force protection on dev portal login

EPSS

Процентиль: 36%
0.00153
Низкий

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.3
nvd
больше 4 лет назад

It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks.

CVSS3: 7.3
github
больше 3 лет назад

It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks.

EPSS

Процентиль: 36%
0.00153
Низкий

5.6 Medium

CVSS3