CVE-2021-20252 - CVE House
Back to Database
Status published Medium CVE-2021-20252

A flaw was found in Red Hat 3scale API Management...

Vulnerability Description

A flaw was found in Red Hat 3scale API Management Platform 2. The 3scale backend does not perform preventive handling on user-requested date ranges in certain queries allowing a malicious authenticated user to submit a request with a sufficiently large date range to eventually yield an internal server error resulting in denial of service. The highest threat from this vulnerability is to system availability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-20252

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

3scale/backend
Vulnerable Versions:
As shipped by Red Hat 3scale API Management Platform 2

Timeline

Official Publish: February 23rd, 2021
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)