CVE-2021-3584

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
23/12/2021
Last modified:
05/01/2022

Description

A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threat from this vulnerability is to confidentiality, integrity and availability of system. Fixed releases are 2.4.1, 2.5.1, 3.0.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:* 2.4.1 (excluding)
cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:* 2.5.0 (including) 2.5.1 (excluding)
cpe:2.3:a:theforeman:foreman:3.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:3.0.0:rc2:*:*:*:*:*:*
cpe:2.3:o:redhat:satellite:6.0:*:*:*:*:*:*:*