Lucene search

K
cvelistRedhatCVELIST:CVE-2021-3589
HistoryMar 23, 2022 - 7:46 p.m.

CVE-2021-3589

2022-03-2319:46:10
CWE-306
redhat
www.cve.org
6
foreman ansible
authorization flaw
access control

AI Score

7.8

Confidence

High

EPSS

0.001

Percentile

37.0%

An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CNA Affected

[
  {
    "product": "Foreman Ansible",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Affects foreman_ansible-2.0.0 and above."
      }
    ]
  }
]

AI Score

7.8

Confidence

High

EPSS

0.001

Percentile

37.0%