{"id":"CVE-2021-20259","aliases":["GHSA-f2rp-4rv7-fc95"],"url":"https://o3.security/vulnerability/CVE-2021-20259","summary":"Exposure of Sensitive Information to an Unauthorized Actor in foreman_fog_proxmox","details":"A flaw was found in the Foreman project. The Proxmox compute resource exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Versions before foreman_fog_proxmox 0.13.1 are affected","published":"2021-06-07T21:15:07.950Z","modified":"2026-07-09T00:37:41.168286Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"RubyGems","name":"foreman_fog_proxmox","fixedVersion":"0.13.1"}],"fix":null,"references":[{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1932144"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T00:37:41.168286Z"}}