Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r2mj-49jv-4jq7

Опубликовано: 03 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.

A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.

EPSS

Процентиль: 25%
0.00088
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.7
redhat
больше 2 лет назад

A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.

CVSS3: 6.7
nvd
больше 2 лет назад

A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.

CVSS3: 6.7
debian
больше 2 лет назад

A sensitive information exposure vulnerability was found in foreman. C ...

EPSS

Процентиль: 25%
0.00088
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-200