Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-4886

Опубликовано: 03 окт. 2023
Источник: redhat
CVSS3: 6.7
EPSS Низкий

Описание

A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.

Отчет

This flaw has a limited impact on security, as candlepin's individual stores' privileges are limited to root and tomcat only. Therefore, the impact is limited to highly privileged users.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2230135foreman: World readable file containing secrets

EPSS

Процентиль: 19%
0.00273
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
nvd
почти 3 года назад

A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.

CVSS3: 6.7
debian
почти 3 года назад

A sensitive information exposure vulnerability was found in foreman. C ...

CVSS3: 6.7
github
почти 3 года назад

A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.

EPSS

Процентиль: 19%
0.00273
Низкий

6.7 Medium

CVSS3