Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-3590


A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.


Published

2022-08-22T15:15:13.583

Last Modified

2024-11-21T06:21:55.123

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-200
  • Type: Primary
    CWE-319

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application theforeman foreman ≥ 1.6.0 Yes
Application redhat satellite 6.0 Yes

References