First published: Tue Dec 20 2016(Updated: )
foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able to view passwords, allowing them to access those systems.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/foreman-debug | <1.15.0 | 1.15.0 |
The Foreman | <1.15.0 | |
Red Hat Satellite | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9593 is considered a high severity vulnerability due to the exposure of sensitive information such as passwords.
To fix CVE-2016-9593, upgrade foreman-debug to version 1.15.0 or later.
CVE-2016-9593 was reported by Pavel Moravec of Red Hat.
CVE-2016-9593 is a logging vulnerability that allows unauthorized access to sensitive information.
All versions of foreman-debug prior to 1.15.0 are affected by CVE-2016-9593.