Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14825

Опубликовано: 09 авг. 2019
Источник: redhat
CVSS3: 4.1
EPSS Низкий

Описание

A cleartext password storage issue was discovered in Katello, versions 3.x.x.x before katello 3.12.0.9. Registry credentials used during container image discovery were inadvertently logged without being masked. This flaw could expose the registry credentials to other privileged users.

A cleartext password storage issue was discovered in Katello. Registry credentials used during container image discovery were inadvertently logged without being masked. This flaw could expose the registry credentials to other privileged users.

Дополнительная информация

Статус:

Low
Дефект:
CWE-312
https://bugzilla.redhat.com/show_bug.cgi?id=1739485katello: registry credentials are captured in plain text during repository discovery

EPSS

Процентиль: 36%
0.00152
Низкий

4.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 2.7
nvd
около 6 лет назад

A cleartext password storage issue was discovered in Katello, versions 3.x.x.x before katello 3.12.0.9. Registry credentials used during container image discovery were inadvertently logged without being masked. This flaw could expose the registry credentials to other privileged users.

CVSS3: 2.7
github
больше 3 лет назад

Katello cleartext password storage issue

EPSS

Процентиль: 36%
0.00152
Низкий

4.1 Medium

CVSS3

Уязвимость CVE-2019-14825