PT-2021-20784 · Foreman+1 · Foreman+1
Evgeni Golov
+1
·
Published
2021-04-26
·
Updated
2024-07-27
·
CVE-2021-3494
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Foreman versions prior to 2.5.0
Description:
A flaw in the smart proxy of Foreman, which provides a restful API to various sub-systems, can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman smart proxy does not check the SSL certificate, allowing an unauthenticated attacker to perform actions in FreeIPA if certain conditions are met. The highest threat from this flaw is to system confidentiality.
Recommendations:
For versions prior to 2.5.0, update to version 2.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the FreeIPA module of the Foreman smart proxy to minimize the risk of exploitation. Avoid using the smart proxy's restful API for sensitive operations until the issue is resolved.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Foreman