A vulnerability was found in the way Satellite 6 installer logs the calls to Candlepins cpdb. The /var/log/candlepin/cpdb.log log file permissions allows a non privileged user to read credentials information from the log files.
Bug report: https://bugzilla.redhat.com/showbug.cgi?id=1692703
An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database.
A cross-site scripting vulnerability was found in foreman in pages where facts are submitted through insertion of HTML in its name or value.
Upstream bug:
http://projects.theforeman.org/issues/21519
An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Red Hat Satellite, independent of the organization the host belongs to. This flaw affects all Red Hat Satellite 6 versions.
A flaw was found in Pulp. Importers and distributors have a "lastoverrideconfig" object which is exposed via the API. In several cases, secrets are passed into overrideconfig when triggering a task. If these config items are given, they're stored in lastoverrideconfig and then become readable to all users with read access on the distributor/importer. Since Pulp installations internally have widely shared read-only accounts which allows everyone to freely data mine / build applications on top of our Pulp without administrative hassle, saved credentials might be accidentally revealed through the API to unwanted users.
A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the username and password used to connect to the compute resource.