PT-2021-20364 · Confluent · Confluent Ansible

Octav Opaschi

·

Published

2021-09-29

·

Updated

2021-10-07

·

CVE-2021-33924

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Confluent Ansible (cp-ansible) versions 5.5.0 through 6.0.0
Description: The issue is related to Incorrect Access Control via an auxiliary component, allowing remote attackers to access sensitive information.
Recommendations: For versions 5.5.0 through 6.0.0, update to a version that fixes the Incorrect Access Control issue to prevent remote attackers from accessing sensitive information.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-33924

Affected Products

Confluent Ansible