A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficiently high privileges, such as root, to retrieve the Candlepin plaintext password.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Foreman | Theforeman | * | 1.24.1.22 (excluding) |
Red Hat Satellite 6.7 for RHEL 7 | RedHat | ansiblerole-satellite-receptor-installer-0:0.6.6.1-1.el7sat | * |
Red Hat Satellite 6.7 for RHEL 7 | RedHat | foreman-0:1.24.1.25-1.el7sat | * |
Red Hat Satellite 6.7 for RHEL 7 | RedHat | foreman-installer-1:1.24.1.22-1.el7sat | * |
Red Hat Satellite 6.7 for RHEL 7 | RedHat | pulp-0:2.21.0.2-1.el7sat | * |
Red Hat Satellite 6.7 for RHEL 7 | RedHat | python-receptor-satellite-0:1.0.1-2.el7sat | * |
Red Hat Satellite 6.7 for RHEL 7 | RedHat | satellite-0:6.7.3-1.el7sat | * |
Red Hat Satellite 6.7 for RHEL 7 | RedHat | tfm-rubygem-foreman_ansible-0:4.0.3.7-1.el7sat | * |
Red Hat Satellite 6.7 for RHEL 7 | RedHat | tfm-rubygem-foreman_remote_execution-0:2.0.10.2-1.el7sat | * |
Red Hat Satellite 6.7 for RHEL 7 | RedHat | tfm-rubygem-foreman-tasks-0:0.17.5.7-1.el7sat | * |
Red Hat Satellite 6.7 for RHEL 7 | RedHat | tfm-rubygem-katello-0:3.14.0.27-1.el7sat | * |
Red Hat Satellite 6.7 for RHEL 7 | RedHat | ansiblerole-satellite-receptor-installer-0:0.6.6.1-1.el7sat | * |
Red Hat Satellite 6.7 for RHEL 7 | RedHat | foreman-0:1.24.1.25-1.el7sat | * |
Red Hat Satellite 6.7 for RHEL 7 | RedHat | foreman-installer-1:1.24.1.22-1.el7sat | * |
Red Hat Satellite 6.7 for RHEL 7 | RedHat | pulp-0:2.21.0.2-1.el7sat | * |
Red Hat Satellite 6.7 for RHEL 7 | RedHat | python-receptor-satellite-0:1.0.1-2.el7sat | * |
Red Hat Satellite 6.7 for RHEL 7 | RedHat | satellite-0:6.7.3-1.el7sat | * |
Red Hat Satellite 6.7 for RHEL 7 | RedHat | tfm-rubygem-foreman_ansible-0:4.0.3.7-1.el7sat | * |
Red Hat Satellite 6.7 for RHEL 7 | RedHat | tfm-rubygem-foreman_remote_execution-0:2.0.10.2-1.el7sat | * |
Red Hat Satellite 6.7 for RHEL 7 | RedHat | tfm-rubygem-foreman-tasks-0:0.17.5.7-1.el7sat | * |
Red Hat Satellite 6.7 for RHEL 7 | RedHat | tfm-rubygem-katello-0:3.14.0.27-1.el7sat | * |