CVE-2021-20259: Infoleak
A flaw was found in the Foreman project. The Proxmox compute resource exposes the password through the API to an authenticated local attacker with viewhosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Versions before foremanfogproxmox 0.13.1 are affected
Other sources
A password leak was identified on Foreman project which will expose Proxmox compute resource password in plaintext through the compute host API.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-20259?
CVE-2021-20259 is a vulnerability found in the Foreman project where the Proxmox compute resource exposes the password through the API to an authenticated local attacker with view_hosts permission.
What is the severity of CVE-2021-20259?
CVE-2021-20259 has a severity rating of 7.8 (high).
How does CVE-2021-20259 affect data confidentiality and integrity?
CVE-2021-20259 poses a threat to data confidentiality and integrity.
How does CVE-2021-20259 impact system availability?
CVE-2021-20259 can impact system availability.
How do I fix CVE-2021-20259?
To fix CVE-2021-20259, update to version 0.13.1 or later of the ForemanFogProxmox package.