Improper Authorization Affecting foreman_ansible package, versions <2.0.0
Threat Intelligence
EPSS
0.09% (38th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RUBY-FOREMANANSIBLE-1303095
- published 10 Jun 2021
- disclosed 8 Jun 2021
- credit Unknown
Introduced: 8 Jun 2021
CVE-2021-3589 Open this link in a new tabHow to fix?
Upgrade foreman_ansible
to version 2.0.0 or higher.
Overview
foreman_ansible is an Ansible integration with Foreman.
Affected versions of this package are vulnerable to Improper Authorization. A authenticated attacker with certain permissions to create and run Ansible jobs is able to access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
References
CVSS Scores
version 3.1