VDB
CVE-2021-3814
CVE-2021-3814
PUBLISHED
CVSS 7.5 HIGH
It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.
EPSS 1.16% · 65.8th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
1.16%
65.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | 3scale | 0 |
| n/a | 3scale | 3scale 2.11 |
Timeline
- Mar 25, 2022 CVE Published
- Mar 26, 2022 EPSS Score
- May 16, 2022 EPSS Score
- Jul 7, 2022 EPSS Score
- Aug 28, 2022 EPSS Score
- Oct 19, 2022 EPSS Score
- Dec 9, 2022 EPSS Score
- Jan 29, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 12, 2023 EPSS Score
- Jul 2, 2023 EPSS Score
- Aug 23, 2023 EPSS Score