CVE-2021-4142

MEDIUM

Candlepin < 3.1.28-2 - Authentication Bypass

Title source: rule
STIX 2.1

Description

The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.

References (5)

Core 5
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=2034346
Vendor Advisory x_refsource_misc
https://access.redhat.com/security/cve/CVE-2021-4142
Patch, Third Party Advisory x_refsource_misc
https://github.com/candlepin/candlepin/pull/3199
Patch, Third Party Advisory x_refsource_misc
https://github.com/candlepin/candlepin/pull/3197
Third Party Advisory x_refsource_misc
https://github.com/candlepin/candlepin/pull/3198

Scores

CVSS v3 5.5
EPSS 0.0012
EPSS Percentile 30.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-639 CWE-287
Status published
Products (1)
candlepinproject/candlepin 3.1.0 - 3.1.28-2
Published Aug 24, 2022
Tracked Since Feb 18, 2026