Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-2157

Опубликовано: 13 мар. 2025
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 6foremanWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-922
https://bugzilla.redhat.com/show_bug.cgi?id=2351092foreman: Disclosure of Executed Commands and Outputs in Foreman / Red Hat Satellite

EPSS

Процентиль: 8%
0.00029
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
nvd
10 месяцев назад

A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively.

CVSS3: 3.3
debian
10 месяцев назад

A flaw was found in Foreman/Red Hat Satellite. Improper file permissio ...

CVSS3: 3.3
github
10 месяцев назад

A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively.

EPSS

Процентиль: 8%
0.00029
Низкий

3.3 Low

CVSS3