foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debugs logging. An attacker with access to the foreman log file would be able to view passwords, allowing them to access those systems.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Foreman | Theforeman | * | 1.15.0 (excluding) |