CVE Vulnerabilities

CVE-2020-10710

Insufficiently Protected Credentials

Published: Aug 16, 2022 | Modified: Nov 21, 2024
CVSS 3.x
4.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
Ubuntu
root.io logo minimus.io logo echo.ai logo

A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficiently high privileges, such as root, to retrieve the Candlepin plaintext password.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
ForemanTheforeman*1.24.1.22 (excluding)
Red Hat Satellite 6.7 for RHEL 7RedHatansiblerole-satellite-receptor-installer-0:0.6.6.1-1.el7sat*
Red Hat Satellite 6.7 for RHEL 7RedHatforeman-0:1.24.1.25-1.el7sat*
Red Hat Satellite 6.7 for RHEL 7RedHatforeman-installer-1:1.24.1.22-1.el7sat*
Red Hat Satellite 6.7 for RHEL 7RedHatpulp-0:2.21.0.2-1.el7sat*
Red Hat Satellite 6.7 for RHEL 7RedHatpython-receptor-satellite-0:1.0.1-2.el7sat*
Red Hat Satellite 6.7 for RHEL 7RedHatsatellite-0:6.7.3-1.el7sat*
Red Hat Satellite 6.7 for RHEL 7RedHattfm-rubygem-foreman_ansible-0:4.0.3.7-1.el7sat*
Red Hat Satellite 6.7 for RHEL 7RedHattfm-rubygem-foreman_remote_execution-0:2.0.10.2-1.el7sat*
Red Hat Satellite 6.7 for RHEL 7RedHattfm-rubygem-foreman-tasks-0:0.17.5.7-1.el7sat*
Red Hat Satellite 6.7 for RHEL 7RedHattfm-rubygem-katello-0:3.14.0.27-1.el7sat*
Red Hat Satellite 6.7 for RHEL 7RedHatansiblerole-satellite-receptor-installer-0:0.6.6.1-1.el7sat*
Red Hat Satellite 6.7 for RHEL 7RedHatforeman-0:1.24.1.25-1.el7sat*
Red Hat Satellite 6.7 for RHEL 7RedHatforeman-installer-1:1.24.1.22-1.el7sat*
Red Hat Satellite 6.7 for RHEL 7RedHatpulp-0:2.21.0.2-1.el7sat*
Red Hat Satellite 6.7 for RHEL 7RedHatpython-receptor-satellite-0:1.0.1-2.el7sat*
Red Hat Satellite 6.7 for RHEL 7RedHatsatellite-0:6.7.3-1.el7sat*
Red Hat Satellite 6.7 for RHEL 7RedHattfm-rubygem-foreman_ansible-0:4.0.3.7-1.el7sat*
Red Hat Satellite 6.7 for RHEL 7RedHattfm-rubygem-foreman_remote_execution-0:2.0.10.2-1.el7sat*
Red Hat Satellite 6.7 for RHEL 7RedHattfm-rubygem-foreman-tasks-0:0.17.5.7-1.el7sat*
Red Hat Satellite 6.7 for RHEL 7RedHattfm-rubygem-katello-0:3.14.0.27-1.el7sat*

Potential Mitigations

References