CVE-2024-12125: 3scale Porta

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A flaw was found in the 3scale Developer Portal. When creating or updating an account in the Developer Portal UI it is possible to modify fields explicitly configured as read-only or hidden, allowing an attacker to modify restricted information.

Affected products

  • 3scale Porta: before 3scale-2.16.0-GA (fixed in 3scale-2.16.0-GA)
  • Red Hat Red Hat 3scale API Management Platform 2

Published 2025-11-06. Last modified 2026-06-17.