Red hat 3scale api management platform 2
This hub aggregates every CVE we track for Red hat 3scale api management platform 2, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
8
CVEs tracked
0
Critical
3
High
0
In CISA KEV
Severity distribution
MEDIUM5HIGH3
Monthly trend
0
2
0
0
0
1
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 8 most recently published vulnerabilities affecting Red hat 3scale api management platform 2.
- CVE-2024-121253scale-porta: readonly fields not validated server-side7.5
- CVE-2024-11831Npm-serialize-javascript: cross-site scripting (xss) in serialize-javascript5.4
- CVE-2024-10295Gateway: apicast basic auth bypass via malformed base64 headerssending non-base64 'basic' auth with special characters causes apicast to incorrectly authenticate a request7.5
- CVE-2024-9671System: pdf invoices of the developer users can be seen if the url is known5.3
- CVE-2024-0560Apicast: use_3scale_oidc_issuer_endpoint of token introspection policy isn't compatible with rh-sso 7.5 or later versions6.3
- CVE-2023-49103scale-admin-portal: logged out users tokens can be accessed5.5
- CVE-2023-5349Draw while calling getdrawinfo()5.3
- CVE-2023-0456Apicast proxies the api call with incorrect jwt token to the api backend without proper authorization check7.4
Product normalization is registry-driven with AI assist and human review. How it works