ZeroHour

CVE-2021-4142

CVSS 3.1
5.5 medium
EPSS
<1%p7
Published
()
Modified
Description

The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.

Vendors
candlepinproject
Products
candlepin
Weakness
CWE-639, CWE-287
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.