CVE-2021-3590: Infoleak
A credential leak vulnerability was found in Foreman through Azure Compute Profile. This flaw exposes the compute profile credentials to the all authenticated users with "viewcomputeprofiles" permission.
Other sources
A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-3590?
CVE-2021-3590 is a vulnerability found in the Foreman project that exposes Azure Compute Profile password through JSON of the API output.
What is the severity of CVE-2021-3590?
The severity of CVE-2021-3590 is high, with a CVSS score of 8.8.
Which software is affected by CVE-2021-3590?
Theforeman Foreman versions 1.6.0 and above, and Redhat Satellite version 6.0 are affected by CVE-2021-3590.
What is the highest threat from CVE-2021-3590?
The highest threat from CVE-2021-3590 is to data confidentiality and integrity as well as system availability.
How can I fix CVE-2021-3590?
To fix CVE-2021-3590, it is recommended to apply the patches provided by the Foreman project and Redhat Satellite.