Vulnerabilities > Redhat > 3Scale > 2.10.0

DATE CVE VULNERABILITY TITLE RISK
2022-03-25 CVE-2021-3814 Missing Authorization vulnerability in Redhat 3Scale
It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead.
network
low complexity
redhat CWE-862
7.5
2021-05-26 CVE-2020-25634 Missing Authentication for Critical Function vulnerability in Redhat 3Scale and 3Scale API Management
A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials.
network
low complexity
redhat CWE-306
5.4