| Vulnerability Name: | CVE-2021-3414 (CCN-234616) | ||||||||||||
| Assigned: | 2021-02-22 | ||||||||||||
| Published: | 2022-07-18 | ||||||||||||
| Updated: | 2022-09-01 | ||||||||||||
| Summary: | A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage other organizations are also granted. The highest threat from this vulnerability is to data confidentiality. | ||||||||||||
| CVSS v3 Severity: | 8.1 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) 7.1 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:U/RC:R)
7.2 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L/E:U/RL:U/RC:R)
| ||||||||||||
| CVSS v2 Severity: | 8.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:P/A:P)
| ||||||||||||
| Vulnerability Type: | CWE-281 | ||||||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2021-3414 Source: MISC Type: Vendor Advisory https://access.redhat.com/security/cve/CVE-2021-3414 Source: CCN Type: Red Hat Bugzilla - Bug 1926139 (CVE-2021-3414) - CVE-2021-3414 satellite: granular permissions related to organizations with other permissions may lead to confidentiality and integrity breach Source: MISC Type: Issue Tracking, Vendor Advisory https://bugzilla.redhat.com/show_bug.cgi?id=1926139 Source: XF Type: UNKNOWN satellite-cve20213414-sec-bypass(234616) | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||