First published: Thu Feb 18 2021(Updated: )
A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0. A credential leak was identified which will expose Azure Resource Manager's secret key through JSON of the API output. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/tfm-rubygem-foreman_azure_rm | <2.2.0 | 2.2.0 |
Theforeman Foreman Azurerm | <2.2.0 | |
Redhat Satellite | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3413 is a vulnerability found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm before version 2.2.0.
The severity of CVE-2021-3413 is medium, with a CVSS score of 6.3.
The highest threat from CVE-2021-3413 is to data confidentiality and integrity.
To fix CVE-2021-3413, update to version 2.2.0 or later of tfm-rubygem-foreman_azure_rm.
More information about CVE-2021-3413 can be found at the following references: [link1](https://access.redhat.com/security/updates/classification), [link2](https://access.redhat.com/errata/RHSA-2021:4702), [link3](https://bugzilla.redhat.com/show_bug.cgi?id=1930352).