Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-1662


In convert2rhel, there's an ansible playbook named ansible/run-convert2rhel.yml which passes the Red Hat Subscription Manager user password via the CLI to convert2rhel. This could allow unauthorized local users to view the password via the process list while convert2rhel is running. However, this ansible playbook is only an example in the upstream repository and it is not shipped in officially supported versions of convert2rhel.


Published

2022-07-14T15:15:07.983

Last Modified

2024-11-21T06:41:12.243

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-200
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application convert2rhel_project convert2rhel 0.24 Yes
Application convert2rhel_project convert2rhel 0.25 Yes

References