Skip to main content

Vendor/product archive

redhat / 3scale CVEs

Beta · best-effort

8 CVEs tagged to redhat / 3scale0 Critical, 4 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2024-0560

Published Feb 28, 2024

A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is use_3scale_oidc_issuer_endpoint, the Token Introspection poli…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3814

Published Mar 25, 2022

It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and pe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14836

Published May 26, 2021

A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to access unauthorized informati…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10711

Published May 22, 2020

A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO…

CVSS 5.9 · Medium

CVE-2019-14849

Published Dec 12, 2019

A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1