Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2pq5-gq5q-3g2p

Опубликовано: 11 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com.

A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com.

EPSS

Процентиль: 5%
0.00151
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 6.5
redhat
9 дней назад

A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com.

CVSS3: 6.5
nvd
6 дней назад

A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com.

EPSS

Процентиль: 5%
0.00151
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-312