CVE-2021-20290: Medium severity the foreman vulnerability
An improper authorization handling flaw was found in Foreman. The OpenSCAP plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources and also causes a denial of service on the Foreman server. The highest threat from this vulnerability is to integrity and system availability.
Other sources
On Foreman, OpenSCAP plugin for smart-proxy introduce a flaw which allows any client to perform actions of Foreman Server. OpenSCAP plugin and a Client system that has Puppet installed with certs signed by Puppet CA or a Foreman with a client system that has a consumer certificate from the Katello CA; attacker can use this Client's certs to access the OpenSCAP API and perform actions which are only reserved for a Foreman server.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-20290?
CVE-2021-20290 is an improper authorization handling flaw in Foreman that allows authenticated local attackers to access and delete limited resources.
How does CVE-2021-20290 affect Foreman?
CVE-2021-20290 allows foreman clients to execute actions that should be limited to the Foreman Server.
What is the severity of CVE-2021-20290?
CVE-2021-20290 has a severity level of 6.1 (medium).
How can CVE-2021-20290 be fixed?
To fix CVE-2021-20290, update to version 0.9.1 or later of the smart_proxy_openscap package.
Where can I find more information about CVE-2021-20290?
You can find more information about CVE-2021-20290 in the references provided: [Link 1](https://github.com/theforeman/smart_proxy_openscap/pull/80) and [Link 2](https://bugzilla.redhat.com/show_bug.cgi?id=1939701).