CVE-2024-3716: Foreman-installer: candlepin database password being leaked to local users via the process list
A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the process list and allows an attacker to take advantage and obtain the password.
Other sources
In puppet-candlepin shipped with the foreman-installer rpm, when calling /usr/share/candlepin/cpdb with --password, cpdb calls liquibase.sh (which calls java) and that leaks the password in the process list.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3716?
CVE-2024-3716 is considered a moderate severity vulnerability due to the potential for password leakage.
How do I fix CVE-2024-3716?
To fix CVE-2024-3716, update to the latest version of foreman-installer that addresses the flaw in puppet-candlepin.
Who is affected by CVE-2024-3716?
CVE-2024-3716 affects users of the Red Hat Satellite version 6.0 with the foreman-installer.
What is the impact of CVE-2024-3716?
The impact of CVE-2024-3716 is that it may allow unauthorized users to capture sensitive passwords from the process list.
When was CVE-2024-3716 published?
CVE-2024-3716 was published on an unspecified date in 2024.