CVE-2016-9593: High severity the foreman vulnerability
foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able to view passwords, allowing them to access those systems.
Other sources
Pavel Moravec of Red Hat reports:
It was found that foreman-debug did not obfuscate sensitive information (such as passwords) from the katello-installer log file, allowing a user authorized to access the log files created by foreman-debug to gain access to potentially sensitive information.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9593?
CVE-2016-9593 is considered a high severity vulnerability due to the exposure of sensitive information such as passwords.
How do I fix CVE-2016-9593?
To fix CVE-2016-9593, upgrade foreman-debug to version 1.15.0 or later.
Who reported CVE-2016-9593?
CVE-2016-9593 was reported by Pavel Moravec of Red Hat.
What type of vulnerability is CVE-2016-9593?
CVE-2016-9593 is a logging vulnerability that allows unauthorized access to sensitive information.
Which versions of foreman-debug are affected by CVE-2016-9593?
All versions of foreman-debug prior to 1.15.0 are affected by CVE-2016-9593.