CVE-2021-3457: Medium severity theforeman Smart Proxy Shell Hooks vulnerability
An improper authorization handling flaw was found in Foreman. The Shellhooks plugin for the smart-proxy allows Foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources and also causes a denial of service on the Foreman server. The highest threat from this vulnerability is to integrity and system availability.
Other sources
On Foreman, Shellhooks plugin for smart-proxy introduce a flaw which allows any client to perform actions of Foreman Server.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/smart_proxy_shellhooksto a version that resolves this vulnerability.Fixed in 0.9.2
Event History
Frequently Asked Questions
What is CVE-2021-3457?
CVE-2021-3457 is an improper authorization handling flaw in Foreman.
What is the severity level of CVE-2021-3457?
The severity level of CVE-2021-3457 is medium.
Which software is affected by CVE-2021-3457?
Theforeman Smart Proxy Shell Hooks version up to 0.9.2 is affected by CVE-2021-3457.
How can an attacker exploit CVE-2021-3457?
An authenticated local attacker can exploit CVE-2021-3457 to access and delete limited resources and cause denial of service.
Where can I find more information about CVE-2021-3457?
You can find more information about CVE-2021-3457 at this link: https://bugzilla.redhat.com/show_bug.cgi?id=1940990