3scale
Red Hat · 8 CVEs
CVE-2024-0560
MEDIUM
Apicast: use_3scale_oidc_issuer_endpoint of token introspection policy isn't compatible with rh-sso 7.5 or later versio…
Feb 28, 2024
CVE-2021-3814
HIGH
3scale: missing validation of access token
Mar 25, 2022
CVE-2021-3752
HIGH
kernel: possible use-after-free in bluetooth module
Feb 16, 2022
CVE-2021-3412
HIGH
3scale: lack of brute force protection on dev portal login
Jun 1, 2021
CVE-2020-25634
MEDIUM
3scale-system: API docs accessible without permissions
May 26, 2021
CVE-2019-14836
HIGH
3scale: dev portal missing protection against login CSRF
May 26, 2021
CVE-2020-10711
MEDIUM
Kernel: NetLabel: null pointer dereference while receiving CIPSO packet with null category may cause kernel panic
May 22, 2020
CVE-2019-14849
MEDIUM
3scale: user session cookie does not set HTTPOnly
Dec 12, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-0560 | Apicast: use_3scale_oidc_issuer_endpoint of token introspection policy isn't compatible with rh-sso 7.5 or later versions | MEDIUM | 0.49% | Feb 28, 2024 |
| CVE-2021-3814 | 3scale: missing validation of access token | HIGH | 1.16% | Mar 25, 2022 |
| CVE-2021-3752 | kernel: possible use-after-free in bluetooth module | HIGH | 1.74% | Feb 16, 2022 |
| CVE-2021-3412 | 3scale: lack of brute force protection on dev portal login | HIGH | 0.76% | Jun 1, 2021 |
| CVE-2020-25634 | 3scale-system: API docs accessible without permissions | MEDIUM | 0.52% | May 26, 2021 |
| CVE-2019-14836 | 3scale: dev portal missing protection against login CSRF | HIGH | 0.58% | May 26, 2021 |
| CVE-2020-10711 | Kernel: NetLabel: null pointer dereference while receiving CIPSO packet with null category may cause kernel panic | MEDIUM | 3.08% | May 22, 2020 |
| CVE-2019-14849 | 3scale: user session cookie does not set HTTPOnly | MEDIUM | 0.53% | Dec 12, 2019 |
Showing 1 to 8 of 8 CVEs