5
CVSSv2

CVE-2021-3814

Published: 25/03/2022 Updated: 07/04/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat 3scale

Vendor Advisories

No description is available for this CVE ...