CVE-2021-3584
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
23/12/2021
Last modified:
05/01/2022
Description
A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threat from this vulnerability is to confidentiality, integrity and availability of system. Fixed releases are 2.4.1, 2.5.1, 3.0.0.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Base Score 2.0
9.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:* | 2.4.1 (excluding) | |
| cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:* | 2.5.0 (including) | 2.5.1 (excluding) |
| cpe:2.3:a:theforeman:foreman:3.0.0:rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:theforeman:foreman:3.0.0:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:redhat:satellite:6.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



