Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-2157

Опубликовано: 13 мар. 2025
Источник: redhat
CVSS3: 3.3

Описание

A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 6foremanWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-922
https://bugzilla.redhat.com/show_bug.cgi?id=2351092foreman: Disclosure of Executed Commands and Outputs in Foreman / Red Hat Satellite

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
nvd
11 месяцев назад

A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively.

CVSS3: 3.3
debian
11 месяцев назад

A flaw was found in Foreman/Red Hat Satellite. Improper file permissio ...

CVSS3: 3.3
github
11 месяцев назад

A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively.

CVSS3: 3.3
fstec
11 месяцев назад

Уязвимость компонента Foreman программного средства для управления системами Red Hat Satellite, связанная с незащищенным хранением критической информации, позволяющая нарушителю повысить свои привилегии

3.3 Low

CVSS3