CVE-2021-3414
published 2022-08-26CVE-2021-3414: A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage other…
PriorityP343high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.56%
43.3th percentile
A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage other organizations are also granted. The highest threat from this vulnerability is to data confidentiality.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | satellite | — | — |
| redhat | satellite | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
satellite: granular permissions related to organizations with other permissions may lead to confidentiality and integrity breach
vendor_redhat·2021-02-08·CVSS 8.1
CVE-2021-3414 [HIGH] CWE-281 satellite: granular permissions related to organizations with other permissions may lead to confidentiality and integrity breach
satellite: granular permissions related to organizations with other permissions may lead to confidentiality and integrity breach
A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage other organizations are also granted. The highest threat from this vulnerability is to data confidentiality.
A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage other organizations are also granted. The highest threat from this vulnerability is to data confidentiality.
Package: satellite (Red Hat Satellite 6) - Affected
GHSA
GHSA-9g8j-gq2h-2qfx: A flaw was found in satellite
ghsa_unreviewed·2022-08-27
CVE-2021-3414 [HIGH] CWE-281 GHSA-9g8j-gq2h-2qfx: A flaw was found in satellite
A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage other organizations are also granted. The highest threat from this vulnerability is to data confidentiality.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-26
Published