CVE-2021-3494: Medium severity theforeman foreman vulnerability
A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman smart proxy does not check the SSL certificate, thus, an unauthenticated attacker can perform actions in FreeIPA if certain conditions are met. The highest threat from this flaw is to system confidentiality. This flaw affects Foreman versions before 2.5.0.
Other sources
The realmfreeipa module of Foreman smart proxy suffers from a flaw that can be exploited as a man-in-the-middle attack. The module does not check the SSL certificate and if certain conditions are met, can perform actions in FreeIPA as the Foreman user.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/foremanto a version that resolves this vulnerability.Fixed in 2.5.0 - Upgrade
Upgrade
Foreman smart proxyto a version that resolves this vulnerability.Fixed in 2.5.0 - Configuration
Configure the FreeIPA/realm_freeipa module of Foreman smart proxy to check/verify the SSL certificate to prevent man-in-the-middle and unauthorized actions.
FreeIPA module of Foreman smart proxy (realm_freeipa/FreeIPA) SSL certificate verification = enabled
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-3494.
What is the severity of CVE-2021-3494?
The severity of CVE-2021-3494 is medium with a severity value of 5.9.
What is the affected software version?
The affected software version is Foreman up to version 2.5.0.
How does CVE-2021-3494 affect the smart proxy?
CVE-2021-3494 affects the smart proxy by allowing a Man-in-the-Middle attack through the FreeIPA module.
Is authentication required to exploit CVE-2021-3494?
No, authentication is not required to exploit CVE-2021-3494.