RHSA-2021:1129MediumCVSS 7.5

Red Hat Security Advisory: Red Hat 3scale API Management 2.10.0 security update and release

Published
April 8, 2021
Last Modified
August 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2019-14836 — 3scale: dev portal missing protection against login CSRF CVE-2020-9283 — golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic CVE-2020-14040 — golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash

🎯 Affected products5

  • Red Hat 3Scale AMP 2.10
  • 3scale-amp2/3scale-rhel7-operator-metadata@sha256:f698cf1102a1847cba810f5be68c264223a37f6424c3e4902465111b5b74d496_amd64 as a component of Red Hat 3Scale AMP 2.10
  • 3scale-amp2/3scale-rhel7-operator@sha256:655062177bc53b155b87876dc1096530c365f18f9be3ceb0d32aa2d343968f9a_amd64 as a component of Red Hat 3Scale AMP 2.10
  • 3scale-amp2/apicast-rhel7-operator-metadata@sha256:65447df0f16603ea021eaae880865ccfcb4449aab6fc2fd519da554c46987e84_amd64 as a component of Red Hat 3Scale AMP 2.10
  • 3scale-amp2/apicast-rhel7-operator@sha256:ef5c4e42d2ce962a21ff0c61f500c6dd672d07ff7f4bfce039ca6851a0fcbef0_amd64 as a component of Red Hat 3Scale AMP 2.10

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_3scale_api_management/2.10/html-single/installing_3scale/index

🔗 References (6)