CVE-2021-3589: High severity the foreman vulnerability
An attacker with elevated privileges can utilize Ansible functions to carry out actions as the Foreman-proxy user on the system. The prerequisite for this is that the hosts must have already been added to Foreman, and the attacker must have access to one of these hosts. If the attacker already has access to the system, they are deemed trustworthy with a high level of privilege.
Other sources
An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-3589?
CVE-2021-3589 is an authorization flaw found in Foreman Ansible, which allows an authenticated attacker with certain permissions to access hosts through job templates.
What is the severity of CVE-2021-3589?
The severity of CVE-2021-3589 is high, with a severity value of 8.
What is the impact of CVE-2021-3589?
The highest threat from CVE-2021-3589 is to data confidentiality and integrity, as well as system availability.
Which software versions are affected by CVE-2021-3589?
Foreman Ansible version up to 7.1.0 and Redhat Satellite version 6.0 are affected by CVE-2021-3589.
How can I fix CVE-2021-3589?
There is no known fix for CVE-2021-3589 at the moment. It is recommended to follow the provided references for any updates or patches.