First published: Fri Apr 12 2024(Updated: )
A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the process list and allows an attacker to take advantage and obtain the password.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Satellite | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3716 is considered a moderate severity vulnerability due to the potential for password leakage.
To fix CVE-2024-3716, update to the latest version of foreman-installer that addresses the flaw in puppet-candlepin.
CVE-2024-3716 affects users of the Red Hat Satellite version 6.0 with the foreman-installer.
The impact of CVE-2024-3716 is that it may allow unauthorized users to capture sensitive passwords from the process list.
CVE-2024-3716 was published on an unspecified date in 2024.