CVE-2021-3456: High severity the foreman smart proxy vulnerability
An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources and also causes a denial of service on the Foreman server. The highest threat from this vulnerability is to integrity and system availability.
Other sources
On Foreman, Salt plugin for smart-proxy introduce a flaw which allows any client to perform actions of Foreman Server.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw in Foreman?
The vulnerability ID for this flaw in Foreman is CVE-2021-3456.
What is the severity of CVE-2021-3456?
The severity of CVE-2021-3456 is high.
What is the affected software for CVE-2021-3456?
The affected software for CVE-2021-3456 is Theforeman Smart Proxy Salt version up to and including 2.1.5.
What is the CWE ID for CVE-2021-3456?
The CWE ID for CVE-2021-3456 is 863.
How can an attacker exploit CVE-2021-3456?
An authenticated local attacker can exploit CVE-2021-3456 to access and delete limited resources and cause a denial of service.