Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-4142

Опубликовано: 17 янв. 2022
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.

Меры по смягчению последствий

Mitigation for this issue is not available because it doesn't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-639->CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=2034346Satellite: Allow unintended SCA certificate to authenticate Candlepin

EPSS

Процентиль: 31%
0.00118
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
больше 3 лет назад

The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.

CVSS3: 5.5
github
больше 3 лет назад

The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.

EPSS

Процентиль: 31%
0.00118
Низкий

5.5 Medium

CVSS3