CVE-2021-3589

An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
References
Link Resource
https://access.redhat.com/security/cve/CVE-2021-3589 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1969265 Issue Tracking Patch Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:theforeman:foreman_ansible:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:satellite:6.0:*:*:*:*:*:*:*

History

08 Feb 2023, 19:04

Type Values Removed Values Added
CVSS v2 : 6.5
v3 : 9.9
v2 : 6.5
v3 : 8.0

04 Apr 2022, 12:09

Type Values Removed Values Added
CPE cpe:2.3:a:redhat:satellite:6.0:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman_ansible:*:*:*:*:*:*:*:*
CWE CWE-306
First Time Redhat satellite
Theforeman foreman Ansible
Redhat
Theforeman
CVSS v2 : unknown
v3 : unknown
v2 : 6.5
v3 : 9.9
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1969265 - (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1969265 - Issue Tracking, Patch, Vendor Advisory
References (MISC) https://access.redhat.com/security/cve/CVE-2021-3589 - (MISC) https://access.redhat.com/security/cve/CVE-2021-3589 - Vendor Advisory

23 Mar 2022, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-23 20:15

Updated : 2023-12-10 14:22


NVD link : CVE-2021-3589

Mitre link : CVE-2021-3589

CVE.ORG link : CVE-2021-3589


JSON object : View

Products Affected

redhat

  • satellite

theforeman

  • foreman_ansible
CWE
CWE-306

Missing Authentication for Critical Function