Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3523

Опубликовано: 26 апр. 2022
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse. This flaw allows an attacker to bypass security restrictions for an API request when hosting multiple APIs on the same IP address.

A flaw was found in 3Scale APICast, where it incorrectly identified connections for reuse. This flaw allows an attacker to bypass security restrictions for an API request when hosting multiple APIs on the same IP address.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 2apicastNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-281
https://bugzilla.redhat.com/show_bug.cgi?id=1954805apicast: permits auth bypass with connection reuse

EPSS

Процентиль: 37%
0.00164
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 4 года назад

A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse. This flaw allows an attacker to bypass security restrictions for an API request when hosting multiple APIs on the same IP address.

CVSS3: 7.5
github
почти 4 года назад

A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse. This flaw allows an attacker to bypass security restrictions for an API request when hosting multiple APIs on the same IP address.

EPSS

Процентиль: 37%
0.00164
Низкий

6.8 Medium

CVSS3