A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the username and password used to connect to the compute resource.
2018-04-04T21:29:00.353
2024-11-21T03:59:10.560
Modified
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | theforeman | foreman | < 1.6.1 | Yes |
Application | redhat | satellite | 6.4 | Yes |