Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19391

Опубликовано: 08 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com.

Отчет

This Moderate flaw in insights-core allows SSSD LDAP bind passwords and Pacemaker CIB fence device credentials to be included in cleartext within archives uploaded by insights-client. The default insights-client configuration is affected, leading to potential exposure of sensitive credentials to individuals with access to these uploaded archives.

Меры по смягчению последствий

Exclude sssd_config, sssd_conf_d, and cib_xml via /etc/insights-client/file-redaction.yaml, or add keyword/pattern redaction covering ldap_default_authtok and fence passwd/password XML forms, until a patched insights-core is available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Pen Drive Powered by Red Hat Lightspeedpen-drive/pen-drive-scanner-rhel9Fix deferred
Pen Drive Powered by Red Hat Lightspeedpen-drive/pen-drive-scanner-rhel9Fix deferred
Red Hat Certification Program for Red Hat Enterprise Linux 9rhcertification/redhat-certification-cloud-10Fix deferred
Red Hat Certification Program for Red Hat Enterprise Linux 9rhcertification/redhat-certification-cloud-9Fix deferred
Red Hat Enterprise Linux 10insights-coreFix deferred
Red Hat Enterprise Linux 10rhel10-eus/rhel-10.2-bootcFix deferred
Red Hat Enterprise Linux 10rhel10/rhel-bootcFix deferred
Red Hat Enterprise Linux 9insights-coreFix deferred
Red Hat Satellite 6satellite/iop-advisor-engine-rhel9Not affected
Red Hat Satellite 6satellite/iop-insights-engine-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-312
https://bugzilla.redhat.com/show_bug.cgi?id=2513020insights-core: insights-core: Incomplete credential redaction exposes SSSD bind passwords and Pacemaker fence credentials in uploaded archives

EPSS

Процентиль: 5%
0.00151
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
6 дней назад

A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com.

CVSS3: 6.5
github
6 дней назад

A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com.

EPSS

Процентиль: 5%
0.00151
Низкий

6.5 Medium

CVSS3