An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
References
Link Resource
https://access.redhat.com/security/cve/CVE-2021-3589 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1969265 Issue Tracking Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2022-03-23T19:46:10

Updated: 2022-03-23T19:46:10

Reserved: 2021-06-09T00:00:00


Link: CVE-2021-3589

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-03-23T20:15:09.773

Modified: 2023-02-08T19:04:36.607


Link: CVE-2021-3589

JSON object: View

cve-icon Redhat Information

No data.

CWE