CVE-2021-3412

Source
https://cve.org/CVERecord?id=CVE-2021-3412
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-3412.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-3412
Published
2021-06-01T14:15:10.267Z
Modified
2026-07-09T07:51:40.079649Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks.

References

Affected packages

Git / github.com/3scale/apicast

Affected ranges

Type
GIT
Repo
https://github.com/3scale/apicast
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "2.0"
        },
        {
            "last_affected": "2.0"
        }
    ],
    "cpe": "cpe:2.3:a:redhat:3scale_api_management:2.0:*:*:*:*:*:*:*",
    "source": "CPE_STRING"
}

Affected versions

2.*
2.0
Other
v2
v2.*
v2.0.0
v2.0.0-rc1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-3412.json"