CVE-2021-3412

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2021-3412
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3412.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-3412
Published
2021-06-01T14:15:10Z
Modified
2024-09-03T03:50:47.848124Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks.

References

Affected packages

Git / github.com/3scale/apicast

Affected ranges

Type
GIT
Repo
https://github.com/3scale/apicast
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

v0.*

v0.1
v0.2

Other

v2

v2.*

v2.0.0
v2.0.0-alpha1
v2.0.0-beta1
v2.0.0-rc1