SB2017040404 - Information disclosure in Red Hat Satellite 



SB2017040404 - Information disclosure in Red Hat Satellite

Published: April 4, 2017

Security Bulletin ID SB2017040404
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information disclosure (CVE-ID: CVE-2017-2672)

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The weakness exists in the foreman's logging due to improper security restrictions during the adding or registering of images. A remote attacker with access to the foreman log file can view passwords for provisioned systems in the log file that allow to access those systems.

Remediation

Install update from vendor's website.