CVE Vulnerabilities

CVE-2023-4886

Published: Oct 03, 2023 | Modified: Mar 01, 2024
CVSS 3.x
4.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A sensitive information exposure vulnerability was found in foreman. Contents of tomcats server.xml file, which contain passwords to candlepins keystore and truststore, were found to be world readable.

Affected Software

Name Vendor Start Version End Version
Foreman Theforeman * 3.8.0 (excluding)

References