PT-2021-20784 · Foreman+1 · Foreman+1

Evgeni Golov

+1

·

Published

2021-04-26

·

Updated

2024-07-27

·

CVE-2021-3494

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Foreman versions prior to 2.5.0
Description: A flaw in the smart proxy of Foreman, which provides a restful API to various sub-systems, can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman smart proxy does not check the SSL certificate, allowing an unauthenticated attacker to perform actions in FreeIPA if certain conditions are met. The highest threat from this flaw is to system confidentiality.
Recommendations: For versions prior to 2.5.0, update to version 2.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the FreeIPA module of the Foreman smart proxy to minimize the risk of exploitation. Avoid using the smart proxy's restful API for sensitive operations until the issue is resolved.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2597
ALT-PU-2023-4281
ALT-PU-2024-7828
CVE-2021-3494
RHSA-2021:4702

Affected Products

Alt Linux
Foreman