CVE-2018-1097: Infoleak
A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the username and password used to connect to the compute resource.
Other sources
A flaw was found in foreman. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the username and password used to connect to the compute resource.
Upstream bug:
https://projects.theforeman.org/issues/22546
Upstream pull request:
https://github.com/theforeman/foreman/pull/5369
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw?
The vulnerability ID for this flaw is CVE-2018-1097.
What is the severity level of CVE-2018-1097?
The severity level of CVE-2018-1097 is high (8.8).
What is the affected software for CVE-2018-1097?
The affected software for CVE-2018-1097 includes Theforeman Foreman versions up to and exclusive of 1.6.1 and Redhat Satellite version 6.4.
What is the impact of CVE-2018-1097?
CVE-2018-1097 allows users with limited permissions to discover the username and password used to connect to the compute resource in foreman before 1.16.1.
How can I fix CVE-2018-1097?
To fix CVE-2018-1097, you should update Theforeman Foreman to version 1.16.1 or later and Redhat Satellite to version 6.4 or later.