CVE-2021-3412
Last modified
CVE-2021-3412 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks.. EPSS estimates a 0.76% chance of exploitation in the next 30 days.
Description
It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | 3scale | All versions |
| Redhat | 3scale Api Management | 2.0 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1928301Issue Tracking, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1928301Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3412?
How severe is CVE-2021-3412?
How do I fix CVE-2021-3412?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-3410A flaw was found in libcaca v0.99.beta19. A buffer overflow …7.8
- CVE-2021-3411A flaw was found in the Linux kernel in versions prior to 5.…6.7
- CVE-2021-34110WinWaste.NET version 1.0.6183.16475 has incorrect permission…7.8
- CVE-2021-34111Thecus 4800Eco was discovered to contain a command injection…9.8
- CVE-2021-34117SQL Injection vulnerability in SEO Panel 4.9.0 in api/user.a…7.5
- CVE-2021-34119A flaw was discovered in htmodoc 1.9.12 in function parse_pa…7.8
- CVE-2021-34121An Out of Bounds flaw was discovered in htmodoc 1.9.12 in fu…7.8
- CVE-2021-34122The function bitstr_tell at bitstr.c in ffjpeg commit 4ab404…5.5
- CVE-2021-34123An issue was discovered on atasm, version 1.09. A stack-buff…9.8
- CVE-2021-34125An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1…7.5
- CVE-2021-34128LaikeTui 3.5.0 allows remote authenticated users to execute …8.8
- CVE-2021-34129LaikeTui 3.5.0 allows remote authenticated users to delete a…8.1
Are you affected by CVE-2021-3412?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
