CVE-2021-4142 Vulnerability Details
/
/
/
CVE-2021-4142 Metadata Quick Info
CVE Published: 24/08/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2021
Source: redhat |
Vendor: n/a |
Product: candlepin
Status : PUBLISHED
CVE-2021-4142 Description
The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID: CWE-639
CWE Name: CWE-639 - Authorization Bypass Through User-Controlled Key -> CWE-287 - Improper Authentication
Source: n/a
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).