{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "unauthorized users can execute actions that should be reserved for foreman",
    "tracking": {
      "current_release_date": "2026-08-11T14:55:21+00:00",
      "generator": {
        "date": "2026-08-11T14:55:21+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2021-3456",
      "initial_release_date": "2021-03-30T10:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T14:55:21+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Satellite 6.15.0",
            "product": {
              "name": "Red Hat Satellite 6.15.0",
              "product_id": "rhn_satellite_6.15",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:satellite:6"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Satellite 6.16.0",
            "product": {
              "name": "Red Hat Satellite 6.16.0",
              "product_id": "rhn_satellite_6.16",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:satellite:6.16"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Satellite 6.17.0",
            "product": {
              "name": "Red Hat Satellite 6.17.0",
              "product_id": "rhn_satellite_6.17",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:satellite:6.17"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Satellite 6.18.0",
            "product": {
              "name": "Red Hat Satellite 6.18.0",
              "product_id": "satellite_6.18",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:satellite:6.18"
              }
            }
          },
          {
            "category": "product_version",
            "name": "smart_proxy_salt",
            "product": {
              "name": "smart_proxy_salt",
              "product_id": "smart_proxy_salt.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/smart_proxy_salt?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "smart_proxy_salt.src as a component of Red Hat Satellite 6.18.0",
          "product_id": "satellite_6.18:smart_proxy_salt.src"
        },
        "product_reference": "smart_proxy_salt.src",
        "relates_to_product_reference": "satellite_6.18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "smart_proxy_salt.src as a component of Red Hat Satellite 6.17.0",
          "product_id": "rhn_satellite_6.17:smart_proxy_salt.src"
        },
        "product_reference": "smart_proxy_salt.src",
        "relates_to_product_reference": "rhn_satellite_6.17"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "smart_proxy_salt.src as a component of Red Hat Satellite 6.15.0",
          "product_id": "rhn_satellite_6.15:smart_proxy_salt.src"
        },
        "product_reference": "smart_proxy_salt.src",
        "relates_to_product_reference": "rhn_satellite_6.15"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "smart_proxy_salt.src as a component of Red Hat Satellite 6.16.0",
          "product_id": "rhn_satellite_6.16:smart_proxy_salt.src"
        },
        "product_reference": "smart_proxy_salt.src",
        "relates_to_product_reference": "rhn_satellite_6.16"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2021-3456",
      "cwe": {
        "id": "CWE-863",
        "name": "Incorrect Authorization"
      },
      "discovery_date": "2021-03-19T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "rhn_satellite_6.15:smart_proxy_salt.src",
            "rhn_satellite_6.16:smart_proxy_salt.src",
            "rhn_satellite_6.17:smart_proxy_salt.src",
            "satellite_6.18:smart_proxy_salt.src"
          ]
        }
      ],
      "notes": [
        {
          "category": "other",
          "text": "Red Hat Satellite 6 does not ship smart_proxy_salt plugin which is affected by the vulnerability. This flaw affects upstream Foreman only.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources and also causes a denial of service on the Foreman server. The highest threat from this vulnerability is to integrity and system availability.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "rhn_satellite_6.15:smart_proxy_salt.src",
          "rhn_satellite_6.16:smart_proxy_salt.src",
          "rhn_satellite_6.17:smart_proxy_salt.src",
          "satellite_6.18:smart_proxy_salt.src"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2021-3456"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-3456"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-3456"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM"
          },
          "products": [
            "rhn_satellite_6.15:smart_proxy_salt.src",
            "rhn_satellite_6.16:smart_proxy_salt.src",
            "rhn_satellite_6.17:smart_proxy_salt.src",
            "satellite_6.18:smart_proxy_salt.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "rhn_satellite_6.15:smart_proxy_salt.src",
            "rhn_satellite_6.16:smart_proxy_salt.src",
            "rhn_satellite_6.17:smart_proxy_salt.src",
            "satellite_6.18:smart_proxy_salt.src"
          ]
        }
      ],
      "title": "unauthorized users can execute actions that should be reserved for foreman"
    }
  ]
}