Satellite: Allow unintended SCA certificate to authenticate Candlepin
Published Aug 24, 2022
5.5
MEDIUMCVSS 3.1
EPSS 0.17%
Description
The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.
Affected products
- Vendor n/a Product Candlepin Defaultn/a
- Version Affects v3.1.28-2, v3.2.21-1, v4.1.8-1 and earlier are affected.StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Candlepin | n/a |
|
- ≥ 3.1.0 · ≤ 3.1.28-2
- ≥ 3.2.0 · ≤ 3.2.21-1
- ≥ 4.1.0 · ≤ 4.1.8-1
No data.
Red Hat Satellite 6.10 for RHEL 7
candlepin-0:4.0.15-1.el7sat
Fixed · RHSA-2022:0790
Red Hat Satellite 6.11 for RHEL 7
satellite-0:6.11.0-2.el7sat
Fixed · RHSA-2022:5498
Red Hat Satellite 6.11 for RHEL 7
satellite-0:6.11.0-2.el7sat
Fixed · RHSA-2022:5498
Red Hat Satellite 6.11 for RHEL 7
satellite-0:6.11.0-2.el7sat
Fixed · RHSA-2022:5498
Red Hat Satellite 6.11 for RHEL 8
satellite-0:6.11.0-2.el8sat
Fixed · RHSA-2022:5498
Red Hat Satellite 6.11 for RHEL 8
satellite-0:6.11.0-2.el8sat
Fixed · RHSA-2022:5498
Red Hat Satellite 6.11 for RHEL 8
satellite-0:6.11.0-2.el8sat
Fixed · RHSA-2022:5498
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Satellite 6.10 for RHEL 7 | candlepin-0:4.0.15-1.el7sat | Fixed | RHSA-2022:0790 |
| Red Hat Satellite 6.11 for RHEL 7 | satellite-0:6.11.0-2.el7sat | Fixed | RHSA-2022:5498 |
| Red Hat Satellite 6.11 for RHEL 7 | satellite-0:6.11.0-2.el7sat | Fixed | RHSA-2022:5498 |
| Red Hat Satellite 6.11 for RHEL 7 | satellite-0:6.11.0-2.el7sat | Fixed | RHSA-2022:5498 |
| Red Hat Satellite 6.11 for RHEL 8 | satellite-0:6.11.0-2.el8sat | Fixed | RHSA-2022:5498 |
| Red Hat Satellite 6.11 for RHEL 8 | satellite-0:6.11.0-2.el8sat | Fixed | RHSA-2022:5498 |
| Red Hat Satellite 6.11 for RHEL 8 | satellite-0:6.11.0-2.el8sat | Fixed | RHSA-2022:5498 |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is not available because it doesn't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2021-4142 x_refsource_MISCVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2034346 x_refsource_MISCIssue TrackingVendor Advisory
- https://github.com/candlepin/candlepin/pull/3197 x_refsource_MISCPatchThird Party Advisory
- https://github.com/candlepin/candlepin/pull/3198 x_refsource_MISCThird Party Advisory
- https://github.com/candlepin/candlepin/pull/3199 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-4142
- https://www.cve.org/CVERecord?id=CVE-2021-4142
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2021-4142 | x_refsource_MISCVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2034346 | x_refsource_MISCIssue TrackingVendor Advisory | |
| https://github.com/candlepin/candlepin/pull/3197 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/candlepin/candlepin/pull/3198 | x_refsource_MISCThird Party Advisory | |
| https://github.com/candlepin/candlepin/pull/3199 | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-4142 | ||
| https://www.cve.org/CVERecord?id=CVE-2021-4142 |
Change history (0)
No recorded changes yet.