Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-20260

Опубликовано: 26 авг. 2022
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:*

EPSS

Процентиль: 9%
0.00033
Низкий

7.8 High

CVSS3

Дефекты

CWE-200
CWE-522

Связанные уязвимости

CVSS3: 6.3
redhat
почти 5 лет назад

A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 7.8
debian
больше 3 лет назад

A flaw was found in the Foreman project. The Datacenter plugin exposes ...

CVSS3: 7.8
github
больше 3 лет назад

A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

EPSS

Процентиль: 9%
0.00033
Низкий

7.8 High

CVSS3

Дефекты

CWE-200
CWE-522