Skip to main content

Vendor/product archive

redhat / 3scale_api_management CVEs

Beta · best-effort

11 CVEs tagged to redhat / 3scale_api_management0 Critical, 7 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2024-10295

Published Oct 24, 2024

A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A malformed basic authentication he…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4910

Published Nov 6, 2023

A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens page is rendered from the bro…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1414

Published Oct 19, 2022

3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user could use this flaw to inject scripts and possibly gain acces…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14388

Published Jun 2, 2021

A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were not properly enforced. This flaw allows an authenticated us…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14852

Published Mar 18, 2021

A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1.0 protocol. An attacker could target traffic using this weaker protocol and break its encryption, gaining acces…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20252

Published Feb 23, 2021

A flaw was found in Red Hat 3scale API Management Platform 2. The 3scale backend does not perform preventive handling on user-requested date ranges in certain queries allowing a m…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10216

Published Nov 27, 2019

In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could ab…

CVSS 7.8 · High
Showing 1-11 of 11 CVEsPage 1 of 1