CVE-2021-4142
published 2022-08-24CVE-2021-4142: The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple…
PriorityP428medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.17%
6.1th percentile
The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| candlepinproject | candlepin | — | — |
| candlepinproject | candlepin | 3.1.0 – 3.1.28-2 | — |
| candlepinproject | candlepin | 3.2.0 – 3.2.21-1 | — |
| candlepinproject | candlepin | 4.1.0 – 4.1.8-1 | — |
| msrc | microsoft_excel_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_excel_2013_service_pack_1 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_msrc7.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Satellite: Allow unintended SCA certificate to authenticate Candlepin
vendor_redhat·2022-01-17·CVSS 5.5
CVE-2021-4142 [MEDIUM] CWE-639 Satellite: Allow unintended SCA certificate to authenticate Candlepin
Satellite: Allow unintended SCA certificate to authenticate Candlepin
The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.
The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.
Mitigation: Mitigation for this issue is not available because it doesn't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Microsoft
Microsoft Office Graphics Remote Code Execution Vulnerability
vendor_msrc·2021-09-14·CVSS 7.8
CVE-2021-38660 [HIGH] Microsoft Office Graphics Remote Code Execution Vulnerability
Microsoft Office Graphics Remote Code Execution Vulnerability
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Microsoft Office Excel: Microsoft Office Excel
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=7d4bf628-fcc9-4af7-87ad-93a8bcbf1054
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=20044c25-9057-4142-9d0d-c4d82d66b475
GHSA
GHSA-qjqc-gw55-mpmx: The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw
ghsa_unreviewed·2022-08-25
CVE-2021-4142 [MEDIUM] CWE-287 GHSA-qjqc-gw55-mpmx: The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw
The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2021-4142https://bugzilla.redhat.com/show_bug.cgi?id=2034346https://github.com/candlepin/candlepin/pull/3197https://github.com/candlepin/candlepin/pull/3198https://github.com/candlepin/candlepin/pull/3199https://access.redhat.com/security/cve/CVE-2021-4142https://bugzilla.redhat.com/show_bug.cgi?id=2034346https://github.com/candlepin/candlepin/pull/3197https://github.com/candlepin/candlepin/pull/3198https://github.com/candlepin/candlepin/pull/3199
2022-08-24
Published