REDHAT-BUG-1739485: Low severity katello vulnerability
Published Aug 9, 2019
·Updated
Registry credentials are captured in plain text in dynflow task during repository discovery.
Upstream issue:
https://bugzilla.redhat.com/showbug.cgi?id=1730668
Affected Software
1 affected component
Red Hat Katello
Event History
Aug 9, 2019
Data Sourced
via Red Hat·12:33 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1739485?
The severity of REDHAT-BUG-1739485 is considered to be high due to the exposure of sensitive registry credentials.
2
How do I fix REDHAT-BUG-1739485?
To fix REDHAT-BUG-1739485, update to the latest patched version of Red Hat Katello as recommended in the errata.
3
What are the risks associated with REDHAT-BUG-1739485?
The risks associated with REDHAT-BUG-1739485 include unauthorized access to container registries due to plain text exposure of credentials.
4
Who is affected by REDHAT-BUG-1739485?
REDHAT-BUG-1739485 affects users of Red Hat Katello who are involved in repository discovery processes.
5
What types of credentials are impacted by REDHAT-BUG-1739485?
REDHAT-BUG-1739485 impacts registry credentials that are captured in plain text during dynflow task execution.