First published: Tue Mar 24 2020(Updated: )
A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficiently high privileges, such as root, to retrieve the Candlepin plaintext password.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Theforeman Foreman | <1.24.1.22 | |
redhat/foreman-installer | <1.24.1.22 | 1.24.1.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10710 is a vulnerability that allows an attacker with root privileges to retrieve the Candlepin plaintext password while updating Red Hat Satellite through the satellite-installer.
The severity of CVE-2020-10710 is medium with a CVSS score of 4.4.
Theforeman Foreman version up to and excluding 1.24.1.22 and redhat/foreman-installer version up to and excluding 1.24.1.22 are affected by CVE-2020-10710.
An attacker with sufficiently high privileges, such as root, can exploit CVE-2020-10710 to retrieve the Candlepin plaintext password.
Yes, upgrading to versions higher than 1.24.1.22 for Theforeman Foreman and redhat/foreman-installer will fix the vulnerability.