CVE-2021-3589
published 2022-03-23CVE-2021-3589: An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through…
PriorityP342high8CVSS 3.1
AVNACHPRHUINSCCHIHAH
EPSS
1.03%
60.1th percentile
An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | satellite | — | — |
| theforeman | foreman_ansible | < 7.1.0 | 7.1.0 |
| theforeman | foreman_ansible | — | — |
| theforeman | foreman_ansible | >= 0 < 2.0.0 | 2.0.0 |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
foreman_ansible: authenticated user can access host through job_template
vendor_redhat·2021-06-08·CVSS 8.0
CVE-2021-3589 [HIGH] CWE-306 foreman_ansible: authenticated user can access host through job_template
foreman_ansible: authenticated user can access host through job_template
An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Package: tfm-rubygem-foreman_ansible (Red Hat Satellite 6) - Affected
OSV
Missing Authentication for Critical Function in Foreman Ansible
osv·2022-03-24
CVE-2021-3589 [HIGH] Missing Authentication for Critical Function in Foreman Ansible
Missing Authentication for Critical Function in Foreman Ansible
An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
GHSA
Missing Authentication for Critical Function in Foreman Ansible
ghsa·2022-03-24
CVE-2021-3589 [HIGH] CWE-306 Missing Authentication for Critical Function in Foreman Ansible
Missing Authentication for Critical Function in Foreman Ansible
An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-03-23
Published