foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able to view passwords, allowing them to access those systems.
2018-04-16T15:29:00.297
2024-11-21T03:01:28.410
Modified
CVSSv3.0: 4.7 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | theforeman | foreman | < 1.15.0 | Yes |
Application | redhat | satellite | 6.0 | Yes |