PT-2022-10476 · Unknown · Foreman Ansible

Yadnyawalk Tale

·

Published

2022-03-23

·

Updated

2023-02-08

·

CVE-2021-3589

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Foreman Ansible (affected versions not specified)
Description An authorization flaw was found, allowing an authenticated attacker with certain permissions to create and run Ansible jobs to access hosts through job templates. This poses a threat to data confidentiality and integrity, as well as system availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3589
GHSA-VVFF-6WRR-4G7Q

Affected Products

Foreman Ansible