CVE-2021-4142

MEDIUM

Candlepin 3.1.0-3.1.28-2 - Authentication Bypass via SCA Certificate

Title source: llm
STIX 2.1

Description

The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.

References (5)

Core 5
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=2034346
Vendor Advisory x_refsource_misc
https://access.redhat.com/security/cve/CVE-2021-4142
Patch, Third Party Advisory x_refsource_misc
https://github.com/candlepin/candlepin/pull/3199
Patch, Third Party Advisory x_refsource_misc
https://github.com/candlepin/candlepin/pull/3197
Third Party Advisory x_refsource_misc
https://github.com/candlepin/candlepin/pull/3198

Scores

CVSS v3 5.5
EPSS 0.0017
EPSS Percentile 6.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-287 CWE-639
Status published
Products (1)
candlepinproject/candlepin 3.1.0 - 3.1.28-2
Published Aug 24, 2022
Tracked Since Feb 18, 2026