CVE Vulnerabilities

CVE-2014-0241

Insufficiently Protected Credentials

Published: Dec 13, 2019 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
4.9 MODERATE
AV:L/AC:L/Au:N/C:C/I:N/A:N
RedHat/V3
Ubuntu

rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Hammer_cli Theforeman - (including) - (including)
Red Hat Satellite 6.0 RedHat rubygem-hammer_cli_foreman-0:0.1.1-16.el7sat *
Red Hat Satellite 6.0 RedHat rubygem-hammer_cli_foreman_tasks-0:0.0.3-3.el7sat *

Potential Mitigations

References