First published: Fri Dec 13 2019(Updated: )
rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Theforeman Hammer Cli | ||
Redhat Satellite | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-0241 is medium with a CVSS score of 5.5.
CVE-2014-0241 allows an attacker to read the world-readable file /etc/hammer/cli.modules.d/foreman.yml, leading to potential information disclosure.
To fix CVE-2014-0241, ensure that the file /etc/hammer/cli.modules.d/foreman.yml is not world-readable and restrict the file permissions accordingly.
Theforeman Hammer Cli and Redhat Satellite version 6.0 are affected by CVE-2014-0241.
For more information about CVE-2014-0241, you can refer to the following references: - [Red Hat Security Advisory](https://access.redhat.com/security/cve/cve-2014-0241) - [CVE-2014-0241 Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-0241)