VDB
CVE-2021-3584
CVE-2021-3584
PUBLISHED
Reported by redhat · Published December 23, 2021
A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threat from this vulnerability is to confidentiality, integrity and availability of system. Fixed releases are 2.4.1, 2.5.1, 3.0.0.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | foreman | foreman 2.4.1, foreman 2.5.1, foreman 3.0.0 |
| n/a | foreman | foreman 2.4.1, foreman 2.5.1, foreman 3.0.0 |
Timeline
- Dec 23, 2021 CVE Published
- Dec 24, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 11, 2022 EPSS Score
- Jun 5, 2022 EPSS Score
- Jul 30, 2022 EPSS Score
- Sep 22, 2022 EPSS Score
- Jan 9, 2023 EPSS Score
- Mar 4, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 27, 2023 EPSS Score
- Aug 14, 2023 EPSS Score