REDHAT-BUG-2274755: Low severity Puppet Candlepin vulnerability
In puppet-candlepin shipped with the foreman-installer rpm, when calling /usr/share/candlepin/cpdb with --password, cpdb calls liquibase.sh (which calls java) and that leaks the password in the process list.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2274755?
The severity of REDHAT-BUG-2274755 is considered moderate due to password leakage in the process list.
How do I fix REDHAT-BUG-2274755?
To fix REDHAT-BUG-2274755, avoid using the --password option with cpdb or upgrade to the latest patched version of Puppet Candlepin.
What is the impact of REDHAT-BUG-2274755?
The impact of REDHAT-BUG-2274755 is the potential exposure of sensitive passwords in the system process list.
Which software is affected by REDHAT-BUG-2274755?
REDHAT-BUG-2274755 affects Puppet Candlepin and the foreman-installer package.
Is there a workaround for REDHAT-BUG-2274755?
A potential workaround for REDHAT-BUG-2274755 is to utilize configuration files for credentials instead of passing passwords directly as arguments.