CVE-2016-4996: High severity red hat satellite vulnerability
discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system journal when used to log in, which allows local users with access to the system journal to obtain the root password by reading the system journal, or by clicking Logs on the console.
Other sources
Thom Carlin of the Red Hat QCI QE Team reports:
Inside discovery-debug, the root password is displayed in plaintext. A redacted sample:
"Discovered by URL: https://<<sat6fqdn>> Entering screenssh TUI executing: echo 'root:<<plaintextpassword>>' | chpasswd && systemctl restart sshd.service Starting Stop Read-Ahead Data Collection... Started Stop Read-Ahead Data Collection."
The output is also available on the console after discovery if you click on Logs and scroll down
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4996?
CVE-2016-4996 is classified as a high-severity vulnerability due to the exposure of root passwords in plaintext.
How do I fix CVE-2016-4996?
To remediate CVE-2016-4996, disable the ssh service on discovered nodes or upgrade to a version of Foreman that is not affected.
Which versions of Foreman are affected by CVE-2016-4996?
Foreman versions prior to 6.2 are affected by CVE-2016-4996.
What impact does CVE-2016-4996 have on my system?
CVE-2016-4996 allows local users to retrieve the root password from the system journal, potentially compromising system security.
Is Red Hat Satellite 6.3 affected by CVE-2016-4996?
Yes, Red Hat Satellite 6.3 is affected by CVE-2016-4996 if the ssh service is enabled on discovered nodes.