CVE-2020-25634: Red Hat 3scale

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive information or modify service APIs. Versions before 3scale-2.10.0-ER1 are affected.

Affected products

  • Red Hat 3scale: before 2.10.0 (fixed in 2.10.0); version 2.10.0 only
  • Red Hat 3scale API Management: version 2.0 only

Published 2021-05-26. Last modified 2026-06-17.