CVE-2021-4142: Medium severity candlepin vulnerability
Red Hat Satellite was affected by an improper authentication in which few factors allow for someone to use the SCA (simple content access) certificate for authentication with Candlepin. The SCA certificates are purposed only for authorizing content access against the CDN (or Pulp in case of Satellite).
Other sources
The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-4142?
CVE-2021-4142 is a vulnerability in the Candlepin component of Red Hat Satellite that allows an attacker to use the SCA certificate for authentication.
How does CVE-2021-4142 affect Red Hat Satellite?
CVE-2021-4142 affects Red Hat Satellite by exposing an improper authentication flaw in the Candlepin component.
What factors could allow an attacker to exploit CVE-2021-4142?
An attacker could exploit CVE-2021-4142 by using the SCA certificate for authentication with Candlepin.
What is the severity of CVE-2021-4142?
CVE-2021-4142 has a severity rating of medium with a CVSS score of 5.5.
How can I fix CVE-2021-4142?
To fix CVE-2021-4142, it is recommended to update Red Hat Satellite to the latest version and apply any relevant patches.