Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xxxj-4ccj-cfw9

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.

The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.

EPSS

Процентиль: 19%
0.00061
Низкий

Дефекты

CWE-200

Связанные уязвимости

redhat
больше 10 лет назад

The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.

nvd
больше 10 лет назад

The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.

EPSS

Процентиль: 19%
0.00061
Низкий

Дефекты

CWE-200