CVE-2021-3584
Published: 23 December 2021
Summary
CVE-2021-3584 is a high-severity OS Command Injection (CWE-78) vulnerability in Theforeman Foreman. Its CVSS base score is 7.2 (High).
Operationally, ranked in the top 34.8% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2021-26892
Vulnerability details
A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threat from this vulnerability is to confidentiality, integrity and availability…
more
of system. Fixed releases are 2.4.1, 2.5.1, 3.0.0.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.