CVE-2021-3412
Summary
| CVE | CVE-2021-3412 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-01 14:15:00 UTC |
| Updated | 2022-06-03 17:24:00 UTC |
| Description | It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks. |
Risk And Classification
Problem Types: CWE-307
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | 3scale | All | All | All | All |
| Application | Redhat | 3scale Api Management | 2.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1928301 – (CVE-2021-3412) CVE-2021-3412 3scale: lack of brute force protection on dev portal login | MISC | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.