CVE Vulnerabilities

CVE-2024-3716

Published: Jun 05, 2024 | Modified: Jun 18, 2024
CVSS 3.x
6.2
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
6.2 LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Ubuntu

A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the –password parameter. This issue leaks the password in the process list and allows an attacker to take advantage and obtain the password.

Affected Software

Name Vendor Start Version End Version
Satellite Redhat 6.0 (including) 6.0 (including)

References