VDB
CVE-2021-3814
CVE-2021-3814
PUBLISHED
CVSS 7.5 HIGH
It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.
EPSS 1.14% · 63.6th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
1.14%
63.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | 3scale | 0 |
| n/a | 3scale | 3scale 2.11 |
Timeline
- Mar 25, 2022 CVE Published
- Mar 26, 2022 EPSS Score
- May 16, 2022 EPSS Score
- Jul 6, 2022 EPSS Score
- Aug 27, 2022 EPSS Score
- Oct 17, 2022 EPSS Score
- Dec 6, 2022 EPSS Score
- Jan 26, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 18, 2023 EPSS Score
- May 8, 2023 EPSS Score
- Jun 28, 2023 EPSS Score