CVE-2021-20290

Source
https://cve.org/CVERecord?id=CVE-2021-20290
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-20290.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-20290
Published
2022-03-25T19:15:08.500Z
Modified
2026-07-08T21:26:40.586499Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
Summary
[none]
Details

An improper authorization handling flaw was found in Foreman. The OpenSCAP plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources and also causes a denial of service on the Foreman server. The highest threat from this vulnerability is to integrity and system availability.

References

Affected packages

Git / github.com/theforeman/smart_proxy_openscap

Affected ranges

Type
GIT
Repo
https://github.com/theforeman/smart_proxy_openscap
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:theforeman:openscap:*:*:*:*:*:foreman:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.9.1"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

0.*
0.0.1
0.1.0
0.3.0
v0.*
v0.4.0
v0.4.1
v0.5.0
v0.5.1
v0.5.3
v0.5.4
v0.6.0
v0.6.1
v0.6.10
v0.6.11
v0.6.2
v0.6.3
v0.6.4
v0.6.5
v0.6.6
v0.6.7
v0.6.8
v0.6.9
v0.7.0
v0.7.1
v0.7.2
v0.7.3
v0.7.4
v0.8.0
v0.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-20290.json"