CVE-2021-3413 PUBLISHED CVSS 6.300000190734863 MEDIUM

A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0. A credential leak was identified which will expose Azure Resource Manager's secret key through JSON of the API output. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

EPSS 0.32% · 54.5th percentile

Risk Scores

CVSS v3.1
6.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.32%
54.5th percentile

Affected Products

VendorProductVersions
redhatsatellite6.0
theforemanforeman_azurerm0
n/aSatellitetfm-rubygem-foreman_azure_rm 2.2.0

Timeline

References

Open in Interactive Console →