REDHAT-BUG-1561723: Medium severity the foreman vulnerability
A flaw was found in foreman. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the username and password used to connect to the compute resource.
Upstream bug:
https://projects.theforeman.org/issues/22546
Upstream pull request:
https://github.com/theforeman/foreman/pull/5369
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1561723?
The severity of REDHAT-BUG-1561723 is assessed as moderate due to the potential for unauthorized users to discover sensitive credentials.
How do I fix REDHAT-BUG-1561723?
To fix REDHAT-BUG-1561723, apply the latest patches provided by The Foreman to secure the affected versions.
Who is affected by REDHAT-BUG-1561723?
Users and administrators of The Foreman, particularly those with limited permissions in oVirt/RHV environments, are affected by REDHAT-BUG-1561723.
What does REDHAT-BUG-1561723 allow attackers to do?
REDHAT-BUG-1561723 allows attackers with limited permissions to access usernames and passwords for connecting to compute resources.
Is there a workaround for REDHAT-BUG-1561723?
Currently, there is no known workaround for REDHAT-BUG-1561723; users should prioritize applying the available fixes.