cbcvebase.
CVE-2021-3589
published 2022-03-23

CVE-2021-3589: An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through…

PriorityP342high8CVSS 3.1
AVNACHPRHUINSCCHIHAH
EPSS
1.03%
60.1th percentile
An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Affected

4 ranges
VendorProductVersion rangeFixed in
redhatsatellite
theforemanforeman_ansible< 7.1.07.1.0
theforemanforeman_ansible
theforemanforeman_ansible>= 0 < 2.0.02.0.0

CVSS provenance

nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.