First published: Thu Oct 14 2021(Updated: )
Red Hat 3scale API Management delivers centralized API management features through a distributed, cloud-hosted layer. It includes built-in features to help in building a more successful API program, including access control, rate limits, payment gateway integration, and developer experience tools.<br>This advisory is intended to use with Container Images, for Red Hat 3scale API Management 2.11.0.<br>Security Fixes:<br><li> PT RHOAM: XSS in 3scale at various places (CVE-2021-3442)</li> <li> aws/aws-sdk-go: CBC padding oracle issue in AWS S3 Crypto SDK for golang (CVE-2020-8911)</li> <li> aws-sdk-go: In-band key negotiation issue in AWS S3 Crypto SDK for golang (CVE-2020-8912)</li> For more details about the security issues, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE pages listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat 3scale |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2021:3851 is classified as important.
You can fix RHSA-2021:3851 by applying the updates provided in the advisory for your affected versions.
RHSA-2021:3851 addresses vulnerabilities in Red Hat 3scale API Management that may affect its security and functionality.
RHSA-2021:3851 affects specific versions of Red Hat 3scale API Management, which can be found in the advisory documentation.
There may be temporary workarounds available for RHSA-2021:3851, but applying the update is the recommended solution.