It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks.
2021-06-01T14:15:10.267
2024-11-21T06:21:26.827
Modified
CVSSv3.1: 7.3 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | 3scale | * | Yes |
Application | redhat | 3scale_api_management | 2.0 | Yes |