CVE-2021-4142

    Dashboard / Vulnerabilities / CVE-2021-4142

    CVE-2021-4142

    Published: 24 Aug 2022Last Modified: 9 Jul 2026

    Summary:

    Details: The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 3c2e908d53d66755895b5debd9e73b3a27d62a0a
    Fixed -None

    Affected versions

    candlepin-3.1.28-1
    candlepin-3.1.28-2
    candlepin-3.1.26-1
    candlepin-3.1.25-1
    candlepin-3.1.24-1
    candlepin-3.1.23-1
    candlepin-3.1.22-1
    candlepin-3.1.21-1
    candlepin-3.1.19-1
    candlepin-3.1.20-1
    candlepin-3.1.18-1
    candlepin-3.1.17-1
    candlepin-3.1.16-1
    candlepin-3.1.15-1
    candlepin-3.1.13-1
    candlepin-3.1.14-1
    candlepin-3.1.12-1
    candlepin-3.1.6-1
    candlepin-3.1.11-1
    candlepin-3.1.10-1
    candlepin-3.1.9-1
    candlepin-3.1.8-1
    candlepin-3.1.7-1
    candlepin-3.1.5-1
    candlepin-3.1.4-1
    candlepin-3.1.3-1
    candlepin-3.1.2-1
    candlepin-3.1.1-1
    candlepin-3.1.0-1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2021-4142 | CVE-DB