A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.
2023-10-03T15:15:40.737
2024-11-21T08:36:11.347
Modified
CVSSv3.1: 6.7 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | theforeman | foreman | < 3.8.0 | Yes |
Application | redhat | satellite | 6.0 | Yes |