PT-2022-10450 · 3Scale · 3Scale Apicast
Chess Hazlett
·
Published
2022-04-27
·
Updated
2022-05-06
·
CVE-2021-3523
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
3Scale APICast versions prior to 2.11.0
Description
A flaw in 3Scale APICast allows an attacker to bypass security restrictions for an API request when hosting multiple APIs on the same IP address. This occurs because the software incorrectly identifies connections for reuse.
Recommendations
For versions prior to 2.11.0, update to version 2.11.0 or later to resolve the issue. As a temporary workaround, consider restricting API requests to prevent bypassing security restrictions when hosting multiple APIs on the same IP address.
Fix
Improper Preservation of Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
3Scale Apicast