First published: Wed Feb 24 2021(Updated: )
A flaw was found in the Foreman project. The Proxmox compute resource exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Versions before foreman_fog_proxmox 0.13.1 are affected
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/foreman_fog_proxmox | <0.13.1 | 0.13.1 |
Theforeman Foremanfogproxmox | <0.13.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20259 is a vulnerability found in the Foreman project where the Proxmox compute resource exposes the password through the API to an authenticated local attacker with view_hosts permission.
CVE-2021-20259 has a severity rating of 7.8 (high).
CVE-2021-20259 poses a threat to data confidentiality and integrity.
CVE-2021-20259 can impact system availability.
To fix CVE-2021-20259, update to version 0.13.1 or later of the ForemanFogProxmox package.