First published: Wed Mar 28 2018(Updated: )
A flaw was found in foreman. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the username and password used to connect to the compute resource. Upstream bug: <a href="https://projects.theforeman.org/issues/22546">https://projects.theforeman.org/issues/22546</a> Upstream pull request: <a href="https://github.com/theforeman/foreman/pull/5369">https://github.com/theforeman/foreman/pull/5369</a>
Affected Software | Affected Version | How to fix |
---|---|---|
The Foreman |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1561723 is assessed as moderate due to the potential for unauthorized users to discover sensitive credentials.
To fix REDHAT-BUG-1561723, apply the latest patches provided by The Foreman to secure the affected versions.
Users and administrators of The Foreman, particularly those with limited permissions in oVirt/RHV environments, are affected by REDHAT-BUG-1561723.
REDHAT-BUG-1561723 allows attackers with limited permissions to access usernames and passwords for connecting to compute resources.
Currently, there is no known workaround for REDHAT-BUG-1561723; users should prioritize applying the available fixes.