Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-4996

Опубликовано: 17 июл. 2017
Источник: nvd
CVSS3: 7
CVSS2: 1.9
EPSS Низкий

Описание

discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system journal when used to log in, which allows local users with access to the system journal to obtain the root password by reading the system journal, or by clicking Logs on the console.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:redhat:satellite:6.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*

EPSS

Процентиль: 12%
0.0004
Низкий

7 High

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-255

Связанные уязвимости

CVSS3: 7.5
redhat
больше 9 лет назад

discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system journal when used to log in, which allows local users with access to the system journal to obtain the root password by reading the system journal, or by clicking Logs on the console.

CVSS3: 7
debian
больше 8 лет назад

discovery-debug in Foreman before 6.2 when the ssh service has been en ...

CVSS3: 7
github
больше 3 лет назад

discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system journal when used to log in, which allows local users with access to the system journal to obtain the root password by reading the system journal, or by clicking Logs on the console.

EPSS

Процентиль: 12%
0.0004
Низкий

7 High

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-255