CVE-2013-0174: Infoleak
Published May 8, 2014
·Updated
The external node classifier (ENC) API in Foreman before 1.1 allows remote attackers to obtain the hashed root password via an API request.
Affected Software
1 affected component
theforeman foreman<=1.0
Event History
May 8, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-0174?
CVE-2013-0174 is classified as a high severity vulnerability due to the potential for unauthorized access to sensitive data.
2
How do I fix CVE-2013-0174?
To fix CVE-2013-0174, you should upgrade to Foreman version 1.1 or later.
3
What kind of attacks can be executed via CVE-2013-0174?
CVE-2013-0174 allows remote attackers to obtain the hashed root password through an API request.
4
Which versions of Foreman are affected by CVE-2013-0174?
CVE-2013-0174 affects all versions of Foreman prior to 1.1.
5
Is it safe to use Foreman with CVE-2013-0174 unpatched?
Using Foreman with CVE-2013-0174 unpatched poses significant security risks and is not recommended.