Red Hat / 3scale
8 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-0560 | Apicast: use_3scale_oidc_issuer_endpoint of token introspection policy isn't compatible with rh-sso 7.5 or later versions | MEDIUM | 6.3 | Feb 28, 2024 |
| CVE-2021-3814 | 3scale: missing validation of access token | HIGH | 7.5 | Mar 25, 2022 |
| CVE-2021-3752 | kernel: possible use-after-free in bluetooth module | HIGH | 7.1 | Feb 16, 2022 |
| CVE-2021-3412 | 3scale: lack of brute force protection on dev portal login | HIGH | 7.3 | Jun 1, 2021 |
| CVE-2020-25634 | 3scale-system: API docs accessible without permissions | MEDIUM | 6.3 | May 26, 2021 |
| CVE-2019-14836 | 3scale: dev portal missing protection against login CSRF | HIGH | 8.8 | May 26, 2021 |
| CVE-2020-10711 | Kernel: NetLabel: null pointer dereference while receiving CIPSO packet with null category may cause kernel panic | MEDIUM | 5.9 | May 22, 2020 |
| CVE-2019-14849 | 3scale: user session cookie does not set HTTPOnly | MEDIUM | 5.4 | Dec 12, 2019 |
Showing 1 to 8 of 8 CVEs